The README, stable versioning, and small dependency surface make the package straightforward to evaluate and adopt. A single registry maintainer, no recent commits, and no security policy leave meaningful uncertainty about ongoing support.
60%
Total Score
50
100
88
50
Only one account has registry publish access. The linked repository is user-owned rather than organization-owned, so this thin maintainer base provides limited evidence of durable maintenance capacity.
The package has only two releases, both published about a day apart, with no release activity during the following 332 days. That limited and stalled history raises abandonment risk for a framework integration package.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the long gap since the latest release, this is evidence that maintenance may have stalled.
Composer build tooling is present, but no security scanning tools were detected. For a small package this is a hygiene limitation, not a standalone severe risk.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, though it does not by itself show a known security issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^v10.0|^v11.10|^v12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.