Documentation, tests, release notes, and security tooling are present. The single-user project has no established history yet, and a medium-confidence workflow finding adds operational risk.
68%
Total Score
67
100
93
88
The package and repository are owned by the same individual account, so there is no organization backing or broader maintainer capacity shown by this signal.
The package is less than one day old with only three releases, so there is not yet enough history to establish maintenance reliability.
No commits or active maintainers were recorded in the last three months, but the repository was pushed recently and the package has just been released. The long-term maintenance record remains unproven.
All three workflows were analyzed, use read-only permissions, and pin all 17 action references. However, a high-confidence medium-severity secrets-inherit finding appears in the release workflow, creating avoidable credential exposure risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 | — | — |
laravel/framework Version ^12.0 || ^13.0 | — | — |
wobqqq/nova-aegis Version ^1.1 || ^2.0 || dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.