The package has a clear README, tests, a small dependency set, and a matching repository with a recent release. Long-term resilience is limited by one active contributor and no documented security policy or scanning.
76%
Total Score
67
100
93
88
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
One contributor made 100% of the one commit in the last 3 months. This creates a genuine continuity risk if that maintainer becomes unavailable.
Composer is used for the build, but no security-scanning tooling was detected. That leaves supply-chain hygiene less transparent than it could be, though it is not evidence of unsafe behavior.
The repository has no security policy. For a small Laravel library this is a transparency gap, but it does not outweigh the recent release, tests, and matching source repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=11 | — | — |
illuminate/database Version >=11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.