The release is clearly documented and has a small dependency surface. Security scanning is absent, and the repository README does not name the package, which weakens transparency.
52%
Total Score
50
100
79
100
The package is only 170 days old, with five releases concentrated in a short burst and four releases in the past year. This shows initial publishing activity but provides little evidence of a sustained release cadence.
The repository has recorded zero commits and zero active maintainers in the past three months, despite the package being relatively new. That is meaningful evidence of limited ongoing maintenance capacity.
The repository name matches the package, but the README does not mention the package name. That weakens confirmation that the linked source and published package are maintained together.
Composer is used for the build, which is appropriate, but no security scanning tools are configured. This is a modest repository hygiene gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nuwave/lighthouse Version ^6.0 | — | — |
illuminate/support Version ^11.0 | ^12.0 | ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.