The package has clear documentation, tests in its repository, release notes, and a matching source project. Its single-release history, one-person publishing base, missing security policy, and unpinned workflow actions leave limited evidence of long-term maintenance and build hygiene.
65%
Total Score
50
79
63
The package runs a post-autoload-dump install-time script. This is common Composer behavior, but it adds installation behavior that should be understood before adoption.
Only one registry account has publishing access. The linked repository is user-owned rather than organization-backed, so there is limited visible redundancy if the maintainer stops work.
The registry namespace and repository owner match, and the owner is identified as an individual. This supports accountability, though it does not provide the redundancy of organization backing.
This is the package's first release, published less than a day ago, so there is no release cadence or maintenance track record yet. The repository's current activity partially supports it, but cannot establish durability.
There are no commits or active maintainers recorded over the last three months, but the project was only released less than a day ago. This is mainly a lack of history rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fortephp/forte Version ^1.1 | — | — |
laravel/framework Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.