The package has clear documentation, tests, an MIT license, and no install-time scripts. It is too new to show sustained maintenance, and its workflow uses six unpinned actions without a security policy.
58%
Total Score
63
100
81
83
Only one registry account has publish access. The linked repository is owned by an individual rather than an organization, so there is limited visible publishing redundancy.
The registry namespace and repository owner are not presented as organization-backed; the repository owner is an individual. This supports the single-maintainer concern but does not independently establish poor health.
All eight releases were published on the same day, with a package age of zero days and a median release interval of only a few minutes. This provides no evidence of sustained maintenance or release discipline yet.
There were no commits or active maintainers in the last three months. Because the project is newly published, this may reflect its age, but it still leaves sustained maintenance unproven.
Composer build tooling is present, but no security scanning tools were detected. That is a modest hygiene gap, not evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
einvoicing/sdk Version ^0.2 | — | — |
illuminate/console Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.