The package is licensed, recently released, and backed by an organization. Its maintenance activity is very small and concentrated in one contributor, while the sole workflow uses an unpinned action.
68%
Total Score
67
100
88
75
One contributor made all recent commits, creating a concentrated maintenance path; organization backing provides some capacity to hand work off but does not remove the current concentration.
Only 2 commits occurred in the last 3 months, showing limited recent maintenance activity even though the release itself is current.
The repository name does not match the package and its README does not mention the package, so the source relationship is less transparent; the README does identify it as a subtree split, which partly explains the mismatch.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, which makes reporting and handling vulnerabilities less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dystcz/dystore-api Version ^1.0.15 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.