Clear licensing, documentation, and a small dependency surface reduce adoption friction. The organization-backed project is young, and its maintenance and security coverage remain limited.
67%
Total Score
67
100
94
88
All recent commits come from one contributor, creating concentration risk; organization backing provides some ability to hand maintenance off but does not show a second active contributor.
Only one commit from one active maintainer was recorded in the last three months, which is a thin maintenance signal despite the recent release.
Composer build tooling is present, but no security-scanning tools were detected, leaving security maintenance less visible.
The repository has no security policy, so users have no documented reporting or response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.