The README, release notes, license, and security scanning provide a clear starting point for adoption. Maintenance evidence is thin, with no commits in three months and only one registry maintainer, while the missing security policy leaves less guidance if problems arise.
58%
Total Score
50
88
75
Only one account has registry publishing access. That does not establish poor project ownership, but it does indicate limited publishing redundancy when combined with the absence of recent commits.
The package is young at 156 days and has four releases, but the latest release was followed by roughly three and a half months without another release. This gives only limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. For a package this young, that is a meaningful sign of currently weak maintenance activity.
The repository has no security policy. Security scanning tools are present, which is helpful, but the absence of published reporting guidance reduces transparency for a package that sends user prompts to external AI providers.
Version 0.4.0 is not a prerelease, but the package remains before a stable major version and has a short release history. Consumers should expect more compatibility change than with a mature stable package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.6 | — | — |
filament/filament Version ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.