Usable with caveats: the release is licensed, tested, clearly backed by its matching repository, and has recent commits. It is a very young project maintained by one contributor, with no security policy and limited evidence of broader adoption.
68%
Total Score
63
100
78
80
The registry namespace and repository are owned by the same individual account rather than an organization, so there is no visible organizational handoff capacity to offset the single-contributor base.
Only two releases have appeared, both within the first day of the package's 86-day history, so there is limited evidence of sustained release maintenance.
One contributor made all six commits in the last three months, leaving maintenance highly dependent on a single person and increasing continuity risk.
There are no open issues or pull requests, but there is also no recent issue or pull-request activity to demonstrate a broader maintenance process.
The repository has no stars, forks, or watchers. This is weak adoption evidence, but popularity is supporting evidence and does not outweigh the package's coherent structure and recent commits.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
stripe/stripe-php Version ^16.0 || ^17.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
laravel/nightwatch Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.