The package has a clear MIT license, a usable README, and release notes for this version. Maintenance is quiet, with no commits or active maintainers in the last three months, and the project has no security scanning or policy.
66%
Total Score
50
88
50
The package has existed since September 2020 and released v1.5.0 in April 2026, but only one release occurred in the last 12 months and the median interval is about 477 days, indicating a slow release cadence.
The repository was updated for this release, but it had zero commits and zero active maintainers during the preceding three months, leaving limited evidence of ongoing maintenance between releases.
Composer build tooling is present, but no security scanning tools were detected, reducing automated visibility into dependency or code risks.
The repository has no published security policy, so users are given no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
eastwest/json Version ^3.0 | — | — |
illuminate/http Version ~5.6|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
starkbank/ecdsa Version ^2.1 | — | — |
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
illuminate/support Version ~5.6|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.