The package has clear licensing, a real README, release notes, and a non-archived organizational project. Maintenance evidence is thin, with only two commits in three months from one contributor, while workflow references are unpinned and security scanning is absent.
70%
Total Score
67
100
88
83
The package is about 18 months old with 19 releases and a median interval of about 9 days, but only two releases occurred in the last 12 months, indicating a slower recent cadence.
One contributor made all two recent commits, concentrating maintenance in a single person. Organization backing provides some handoff capacity, but no second active contributor is shown.
Only two commits were recorded in the last three months, so recent maintenance activity is limited despite the repository having a current release.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security hygiene unverified.
The repository has no formal security policy, although the README provides a direct security contact; this is a modest transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dystcz/dystore-api Version ^1.0.15 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.