The repository is well documented, licensed, tested, and directly tied to the package. All 11 workflow actions are unpinned, and the project has no security-scanning tool, leaving avoidable maintenance and build-integrity gaps.
62%
Total Score
50
75
75
The package is brand new, with only two releases published within the same day, so there is little evidence of sustained maintenance or release stability.
The repository shows zero commits and zero active maintainers over the past three months. Because the project was released only recently, this is concerning but not conclusive evidence of abandonment.
The repository has one star, no forks, and no watchers. This provides little external adoption evidence, though low popularity is less concerning for a package released only hours ago.
Composer build tooling is present, but no security-scanning tool was detected. That leaves a transparency and maintenance gap for a package intended to run in application projects.
Version v0.1.1 is a 0.x release, indicating an alpha-stage API that may change before a mature release, even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.