The package is licensed, well documented, and has a small runtime dependency set. Its single-person project has had no commits for 3 months and no security scanning, which makes ongoing fixes less certain.
55%
Total Score
50
100
88
67
Only one registry publishing account is listed, which limits publishing redundancy. The linked repository is user-owned rather than organization-owned, so no broader project backing compensates for that thin base.
The package has 32 releases in 241 days with very short median intervals, showing strong initial publishing activity, but the latest recorded release is substantially older than the assessment date.
The repository recorded zero commits and zero active maintainers during the last 3 months, a significant warning that maintenance may have stalled.
Composer build tooling is present, but no security scanning tools are configured, leaving an avoidable project hygiene gap.
The repository has no security policy, so there is no stated process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
livewire/livewire Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.