Usable with caveats: it has a clear MIT license, matching source repository, tests, release notes, and safe workflow analysis. However, it is a very new package with no commits in the last three months, only one registry maintainer, and permissive or unspecified workflow permissions.
68%
Total Score
63
100
83
70
A post-autoload-dump install-time script runs during Composer installation. This is an additional supply-chain execution surface, although the signal does not show that the script is malicious or unusually dangerous.
Only one registry account has publishing access. Because the repository is user-owned rather than organization-backed, this represents a thin publishing base and increases continuity risk if that maintainer becomes inactive.
The package is only 195 days old and has two releases, both published within about four hours, so there is limited evidence of sustained maintenance over time.
The repository recorded zero commits and zero active maintainers during the last three months. For a package only 195 days old, that weakens confidence in ongoing maintenance and is the main adoption concern.
There are no open issues or pull requests and no activity in the last month. This is not inherently negative for a small new package, but it provides little evidence of an active user or contributor community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.7 | — | — |
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.