The project is very new, with all four releases arriving within about an hour and a single registry maintainer. It has a clear README, changelog, matching MIT license, and no install-time scripts, but lacks a security policy and has no adoption history yet.
68%
Total Score
50
100
83
83
Only one registry account has publish access. That is consistent with an individual-owned project but leaves limited visible publishing redundancy.
The repository is owned by an individual account rather than an organization, which is consistent with the single-maintainer profile and provides limited institutional backing.
The package is only 57 days old and has four releases, with a median interval of about 39 minutes; this shows active initial publishing but not a mature maintenance record.
The repository has zero stars, forks, and watchers. Because the project is only 57 days old, this is weak supporting evidence rather than a standalone health failure.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest transparency and maintenance-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
myclabs/deep-copy Version ^1.12 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
phpstan/phpdoc-parser Version ^1.0|^2.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.