The package has a clear README, a small coherent source tree, and modest dependencies without install-time scripts. Organization backing and an MIT declaration help, but testing and security-process coverage are limited.
59%
Total Score
75
88
83
Only two releases are recorded, both published within about three hours, and no later release activity is shown over the package's 184-day age. This leaves maintenance continuity unproven.
There were no commits and no active maintainers in the last three months. Given the package's young age, this is a meaningful lack of continuing maintenance evidence.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance-process gap, not evidence that the package is unsafe.
The repository has no security policy. For a package that handles an SMS API token, the missing disclosure and reporting process lowers transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.