Usable with caveats: the release is licensed, tested, documented, and backed by a matching repository, but maintenance appears paused and the project depends on a single publisher with limited security hygiene.
61%
Total Score
63
100
83
90
Only one registry publisher is listed. That is a real continuity risk for a user-owned project because publishing and maintenance capacity are concentrated in one person.
The registry namespace and repository owner both identify the same individual account, and the repository is user-owned. This supports ownership consistency but offers less organizational continuity than an established project team.
There have been 8 releases, including 7 in the last 12 months, but the releases were concentrated in a very short burst and the latest release was about 5 months before collection. This supports initial activity but not ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers over the last 3 months, despite the package being relatively new. That lack of recent work is the strongest abandonment concern.
The repository has only 2 stars, 1 fork, and no watchers. This indicates limited external adoption or review, although popularity alone does not make a small package unhealthy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^9.0 | ^10.0 | ^11.0 | ^12.0 | — | — |
firebase/php-jwt Version ^6.4|^7.0 | — | — |
illuminate/support Version ^9.0 | ^10.0 | ^11.0 | ^12.0 | — | — |
socialiteproviders/manager Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.