The package includes tests, release notes, a clear license, and a repository that matches the package. Its single-person ownership, limited release history, absent security policy, and unpinned workflow actions leave meaningful maintenance and supply-chain hygiene concerns.
68%
Total Score
50
100
83
75
Only one registry account has publish access. The linked project is user-owned rather than organization-backed, so the narrow publishing base provides limited resilience if the maintainer becomes unavailable.
The package has only two releases over 106 days, with the latest release followed by about 103 days without another release. This is limited evidence of sustained maintenance for a young project.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption or review signal for this young package.
The repository uses Composer but reports no security-scanning tools. The missing automated security coverage is a modest transparency and maintenance gap.
The repository has no security policy. For a package handling SMS, OTP, WhatsApp, webhooks, and credentials, the absence of a documented vulnerability-reporting path is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/queue Version ^10.0|^11.0|^12.0 | — | — |
illuminate/events Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.