This is a young but reasonably transparent and actively maintained package: it has three releases over 30 days, a current non-archived repository, two active contributors, organization backing, a matching README, a clear Apache-2.0 license, Composer dependency tooling, Dependabot, and a security policy. The main concerns are its early v0.x maturity, absence of tests and a changelog in both the artifact and repository, very limited repository adoption, and a GitHub Actions workflow with top-level write permissions and pull_request_target usage. It appears usable for adoption with normal caution around its immature API and limited validation history, rather than being an abandonment or registry-health risk.
78%
Total Score
100
100
78
80
The repository has one pull_request_target workflow. Although no untrusted checkout or script injection was detected, this workflow class warrants caution because it can operate with elevated repository context.
A substantial README documents the package’s purpose, requirements, namespace, and design rules, but tests and a changelog are absent in both the artifact and repository; for reusable framework primitives, the missing tests are a genuine validation gap.
Three releases in the first 30 days, with a median interval of about 15 days, show active initial publishing but provide only a short maintenance history.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this leaves little external adoption evidence for a package that is only 30 days old.
The sole workflow declares top-level write permissions. This is broader than a least-privilege configuration and increases workflow compromise impact, despite the absence of other detected workflow hazards.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
fapost/foundation Version ^0.2 | — | — |
illuminate/support Version ^11.0 || ^12.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.