Documentation, tests, and release notes support adoption. The project is new, releases were concentrated within three days, and no repository commits were recorded in the last three months; workflow references are also unpinned.
58%
Total Score
0
83
50
No commits and no active maintainers were recorded during the last three months. For a package released only recently, this is a meaningful maintenance concern.
The package is only 196 days old, with seven releases concentrated between March 6 and March 9, 2026. This shows early publishing activity but does not yet demonstrate sustained maintenance.
Composer is used as the build tool, but no security scanning tools were detected. This is a modest transparency and hygiene gap, not evidence of unsafe code.
The repository has no security policy. That makes vulnerability reporting less transparent, though the absence does not by itself indicate abandonment.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both of its two action references are unpinned, leaving avoidable dependency-update risk in the build.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.0 | — | — |
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/support Version ^11.28|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.