Documentation is thorough, tests exist in the repository, and the release has notes. Two contributors made 57 commits in three months, but the project is young and still prerelease; unpinned workflow actions and no security policy add avoidable risk.
70%
Total Score
75
100
75
50
The repository is owned by a user account rather than an organization, so the small contributor base has no demonstrated organizational backing to compensate for maintenance concentration.
The package is only 97 days old and has three releases, all concentrated within a few hours. This shows active initial iteration but provides limited long-term release history.
There are two open issues and no issues or pull requests were closed in the last month. With only a short project history, this is a limited maintenance concern rather than evidence of abandonment.
The repository has no stars, forks, or watchers. This is weak supporting evidence, but popularity is not decisive for a young, actively maintained package.
Composer build tooling is present, but no security scanning tools were detected. For a package handling webhooks, messaging, and telephony integrations, that is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twilio/sdk Version ^8.0 | — | — |
illuminate/bus Version ^11.0|^12.0|^13.0 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/config Version ^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.