The README, tests, package structure, and matching source repository make the release easy to inspect. It was published today with only two releases, and no security scanning or policy is present, so long-term maintenance remains unproven.
67%
Total Score
83
100
89
88
The package has only two releases, both published today, so there is not yet enough history to establish a durable release cadence or maintenance track record.
There were no commits from active maintainers in the last three months, but the repository and package are brand new today; this is best treated as unproven maintenance rather than evidence of a collapsed project.
Composer build tooling is present, but no security scanning tools were detected. For a small demonstration integration this is a hygiene gap, not a severe dependency risk by itself.
The repository has no security policy. This reduces disclosure transparency, although the package's small, demonstration-only scope limits the practical weight of the gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
3neti/settlement-envelope Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.