Usable with caveats: the release has clear licensing, tests, documentation, and a matching source repository, but the project is less than a day old with only rapid initial releases and no established adoption record. Review future maintenance before making it a core dependency.
68%
Total Score
78
75
The package is less than a day old and has four releases clustered within minutes, so there is not yet enough history to demonstrate sustained maintenance or release stability.
The repository has zero stars, forks, and watchers. Because the package is less than a day old, this is weak evidence rather than a standalone adoption concern, but it provides no external maturity support yet.
Composer build tooling is present, but no security-scanning tool was detected. For a brand-new package this is a modest transparency gap, not evidence that the code is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
The sole GitHub Actions workflow has no top-level token permissions declaration. It has no observed write permissions, but explicitly limiting permissions would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0|^7.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.