The package has clear documentation, tests, a changelog, and a small runtime dependency footprint. Its young project has only one commit from one contributor in the last three months, and registry metadata lists v1.1.1 as latest despite assessing v2.0.1.
62%
Total Score
50
100
81
83
The repository is owned by a user account rather than an organization, so the single-maintainer evidence is not offset by visible organizational backing.
The package is only 103 days old with three releases, and its latest release was about two months ago; this provides limited evidence of long-term maintenance.
All recent commit activity comes from one contributor, leaving no demonstrated backup maintainer for ongoing support.
Only one commit was recorded in the last three months from one active maintainer. For a package this young, that is limited maintenance evidence and raises the risk of slow fixes.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a modest repository hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.