The dependency surface is small and the repository clearly matches the package. Security scanning is absent, and the project has limited demonstrated history, so pin this version deliberately.
62%
Total Score
50
100
83
88
The repository is owned by an individual account rather than an organization, so the limited maintainer evidence provides little visible backing capacity.
This release is about six months old, but it is the package's only release, so there is limited evidence of sustained maintenance or release quality.
The repository recorded no commits and no active maintainers during the last three months, which is concerning for a package with only one release.
Composer is used for the build, but no security scanning tools are configured, leaving a transparency and maintenance gap.
The repository has no security policy, reducing guidance for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.