There is no security policy, and repository testing evidence is limited. The package is small and clearly licensed, but its long-term support capacity is uncertain.
55%
Total Score
100
67
75
The latest release was about four years ago, with no releases in the last 12 months, although the package had four releases and a regular early cadence.
The repository has 1 star, 0 forks, and 1 watcher, providing little community evidence or backup support; low popularity alone is not disqualifying for a small package.
The repository is not archived, which preserves a path for maintenance, but it was last pushed about four years ago and does not offset the inactive release history.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a package that makes external service requests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/support Version ^8.0|^9.0 | — | — |
illuminate/contracts Version ^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.