The package has a clear MIT license, tests, a README, and no install-time scripts. Its workflow dependencies are unpinned and the project has no published security policy.
64%
Total Score
50
100
92
67
The repository is owned by an individual rather than an organization, so long-term continuity depends on a single project owner; this is context rather than proof of poor health.
This is a new package released today with only one release, so there is little evidence of maturity or sustained maintenance yet.
No commits or active maintainers were observed in the last three months. Because the package itself is only one day old, this primarily limits evidence of ongoing maintenance rather than proving abandonment.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a package that sends requests to an external SMS service.
The workflow audit found no dangerous triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
guzzlehttp/guzzle Version ^7.8.2 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.