Usable with caveats: the package is well-documented, tested, licensed, and backed by an organization, but it has only one release and no recorded commits in the last three months. Review its fit carefully before adopting it as a long-term dependency.
68%
Total Score
67
100
78
63
The package uses a post-autoload-dump install lifecycle script. This is an operational consideration, but the signal does not establish that the script is unsafe or unusually invasive.
This is a young package at 127 days old with only one release, so there is limited evidence of sustained maintenance or release maturity.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with only one release, this is the main concern about whether maintenance will continue.
There are no open issues or pull requests and no activity in the last month. The clean issue tracker is not negative by itself, but it provides no evidence of an active user or maintainer community.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone is not decisive for a young package with organization backing and a complete project structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.