Usable with caveats: the release is licensed, tested, documented, non-deprecated, and backed by a matching repository with a recent release. However, the repository had no commits or active maintainers in the last three months and has no security scanning or policy.
72%
Total Score
50
100
88
88
The registry namespace and repository owner match, but the owner is an individual rather than an organization, so the project has limited visible institutional backing.
The package is about one year old with three releases, all within the last 12 months, but releases are spaced roughly three months apart, indicating modest rather than rapid maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release partly compensates for this, but the absence of ongoing development is a meaningful maintenance concern.
Composer is used for builds, but no security scanning tools are configured, leaving less automated coverage for dependency or code risks.
No security policy was found in the repository, which reduces transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ~1.0 || ^2.0 || ^3.0 | — | — |
illuminate/support Version 12.*|13.* | — | — |
illuminate/container Version 6.*|7.*|8.*|9.*|10.*|11.*|12.*|13.* | — | — |
illuminate/filesystem Version 6.*|7.*|8.*|9.*|10.*|11.*|12.*|13.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.