MIT licensing, release notes, and a substantial file tree support adoption. The repository is active and organization-backed, but recent work is sparse and entirely concentrated in one contributor.
65%
Total Score
67
88
50
The package has 51 releases over about 2 years and 10 months, but only 2 releases in the last 12 months. The recent cadence is slower than its historical median of about 6 days, which modestly reduces maintenance confidence.
One contributor made 100% of the 2 recent commits. Although the repository is organization-owned, the observed short-term activity still shows concentrated maintenance capacity.
Only 2 commits were recorded in the last 3 months, with 1 active maintainer. That is ongoing activity, but too little recent change to provide strong maintenance assurance.
Composer is used for builds, but no security-scanning tool was detected. This weakens evidence of routine dependency or code security checks without proving unsafe maintenance.
The repository has no security policy, leaving no documented process for reporting and handling security issues. This is a transparency gap for a package providing an API layer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lunarphp/lunar Version 1.5.0-beta.6 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
laravel-json-api/hashids Version ^3.2 | — | — |
laravel-json-api/laravel Version ^5.1 | — | — |
laravel-json-api/non-eloquent Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.