Usable with caveats: the package is licensed, documented, tested in its repository, and not deprecated or archived. It is only 43 days old, has two releases, and all recent commit activity comes from one contributor, so long-term maintenance is not yet established.
65%
Total Score
50
100
88
90
The registry namespace and repository owner match, but the owner is a user account rather than an organization. The matching ownership supports authenticity, while it provides limited evidence of maintenance capacity.
The package is only 43 days old and has two releases, both published within about 6 hours. This is too little history to establish sustained maintenance, although it is not evidence of abandonment by itself.
One contributor made 100% of the recent commits, leaving no demonstrated contributor redundancy. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this concentration.
Only one commit was recorded in the last three months from one active maintainer. For a package this young that may reflect initial development, but it does not yet demonstrate ongoing maintenance capacity.
The repository uses Composer and contains testing and analysis configuration, but no security scanning tool was detected. The build setup is present, while security-process transparency is limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
ashita-planning/laravel-error-monitor Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.