The package includes tests, a clear README, a matching MIT license, and a read-only workflow permission setup. Its short release history, no recent commits, absent security policy, and entirely unpinned actions leave limited evidence of sustained maintenance and reproducible automation.
62%
Total Score
75
100
79
75
Only two releases appeared, both within roughly 30 minutes on the first day, and no newer release followed during the package's 103-day lifetime. This is limited evidence of an established maintenance cadence.
There were zero commits and zero active maintainers in the last three months. Since the project is only about 103 days old, this may reflect an early pause rather than long-term abandonment, but it still weakens maintenance evidence.
Composer build tooling is present, but no security-scanning tools were detected. For a small PHP library this is a meaningful hygiene gap, though it is not evidence of unsafe code by itself.
The repository has no security policy. That makes vulnerability reporting and response expectations less transparent for a package intended for application integration.
v0.1.1 is not a stable major release, so its API and behavior may still change substantially. It is not marked as a prerelease, which provides a small compensating signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.