Clear installation guidance, tests, licensing, and a small dependency surface reduce adoption friction. The matching, organization-backed repository is active, though the project has limited operating history and no security process is visible.
68%
Total Score
100
100
79
88
The package is only 22 days old, but it has already made five releases with a median interval of about 5 days, showing active early development rather than abandonment.
Composer is used as the build tool, but no security scanning tools are configured. That is a process gap for a young package, though it is not severe on its own.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting expectations unclear.
Version v0.2.3 is not at a stable major version, so compatibility may still change even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
condux/condux Version ^0.1 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.