The package is small and clearly tied to its repository, with a simple dependency surface and no install-time scripts. Its license is declared, but it lacks security scanning and a security policy, while adoption evidence is limited.
61%
Total Score
50
100
81
83
The repository is owned by an individual user rather than an organization, so maintainer capacity may be limited, but the ownership context is at least explicit.
This is a young package with only two releases, both within roughly four days, so there is limited evidence of long-term maintenance or release discipline.
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of uncertain ongoing maintenance for a package released only recently.
The repository has zero stars, forks, and watchers, providing no supporting evidence of adoption or community review; this is cautionary but not decisive for a small package.
Composer is used for builds, but no security scanning tool is configured, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.