Clear documentation, tests, a changelog, and release notes make integration straightforward. The MIT license and recent release support adoption, though workflow references are not pinned and the project has no security policy.
72%
Total Score
63
100
94
63
The package runs post-install and post-update Composer scripts, which add execution during dependency operations and merit review even though the signal does not show malicious behavior.
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor concentration is not visibly compensated by organizational backing.
All recent commits came from one contributor, leaving maintenance dependent on a single person with no demonstrated recent backup.
Only one commit from one active maintainer was recorded in the last three months; this shows recent activity but limited maintenance capacity.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest process gap for supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fab2s/dt0 Version ^2.0.0 | — | — |
illuminate/validation Version ^11.0|^12.0|^13.0 | — | — |
illuminate/translation Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.