A single maintainer, no security policy, and no repository security scanning leave limited maintenance depth and transparency. The package is licensed, documented, non-deprecated, and its repository matches the package.
58%
Total Score
50
100
78
83
Only one registry maintainer is listed, indicating a thin publishing base. This is a real continuity concern because the repository is also owned by an individual rather than an organization.
The repository is owned by an individual user rather than an organization, providing limited visible project backing and little redundancy if the maintainer becomes unavailable.
The package has only one release, published 342 days ago, so there is little evidence of an established release process or ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has not shown recent maintenance activity.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but there is no external adoption signal to offset the limited maintenance history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.21|^10.0|^11.0 | — | — |
illuminate/contracts Version ^9.21|^10.0|^11.0 | — | — |
agrodep/laravel-api-response Version ^1.0 | — | — |
spatie/laravel-package-tools Version ^1.16|^1.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.