The MIT license, release notes, and repository tests improve transparency. Two active contributors and recent commits offset the single registry maintainer, but the v0.x release line has little track record.
70%
Total Score
83
100
86
50
The package runs a post-autoload-dump script during installation, which adds execution during dependency setup and merits ordinary review.
The repository is user-owned rather than organization-owned, so the small two-person contributor base provides limited visible maintenance redundancy.
The package is only 7 days old, despite 8 releases and a median interval of about 1 day, so its long-term maintenance record is unproven.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
v0.6.1 is not a stable major release, which signals an evolving API and less maturity for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/cache Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.