The package has a clear README, tests, and no install-time scripts. Security scanning and a security policy are absent, so pin this version only if you can accept a small, single-owner project.
68%
Total Score
50
100
81
88
The repository is owned by a user account rather than an organization, so the single-contributor maintenance concentration is not offset by visible organizational backing.
The package is only 47 days old with two releases, so its maintenance record is still too short to establish maturity, although it has released recently.
One contributor made all recorded commits in the last three months, leaving maintenance dependent on a single person with no demonstrated handoff capacity.
Only one commit was recorded in the last three months, but the repository is only 47 days old and was updated on the assessment date; this limits the maintenance evidence rather than indicating abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap for a package handling authenticated API access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^0.7 | — | — |
illuminate/http Version ^13.0 | — | — |
illuminate/routing Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.