Usable with caveats: the repository is active, correctly linked, licensed, and backed by an organization, but this is a brand-new pre-1.0 package with only one contributor and no security policy. Consider it for adoption only if you can tolerate early-project churn.
72%
Total Score
83
100
81
75
The package is less than a day old with only 2 releases, so there is not enough history to demonstrate long-term maintenance or release reliability.
All 13 recent commits came from one contributor, creating concentration risk. The organization-owned repository provides some ability to hand maintenance off, so this is not a severe concern.
Composer build tooling is present, supporting a defined build process. No security scanning tools were detected, which is a minor gap but not decisive for this very new package.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though the package's recent age and lack of other severe indicators reduce its weight.
Version v0.1.1 is not a stable-major release, indicating an early API that may change. The explicit release notes for this version provide some transparency about the change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0|^3.0 | — | — |
illuminate/view Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/container Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.