The package artifact is substantial and includes extensive tests. Installation runs a post-autoload-dump script, while the repository could not be found for maintenance and provenance checks.
35%
Total Score
63
75
The package is brand new, with its first and latest release on the same day and 55 releases issued in that period. This leaves maintenance maturity and release discipline unproven.
The manifest declares a proprietary license while the artifact contains an MIT-0 license file, creating a material licensing ambiguity for adopters. The README also describes a non-commercial license, so the conflict should be resolved before adoption.
The package runs a post-autoload-dump lifecycle script during Composer operations. Such scripts can be legitimate for Laravel integration, but they increase installation behavior that adopters must understand.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
coderstm/laravel-themer Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.