Documentation and test coverage are solid, and the package has a clear organization-backed repository. Its young v0.2 line and no commits in the last three months leave maintenance continuity unproven.
61%
Total Score
50
100
81
75
There were zero commits and zero active maintainers in the last three months, despite the repository being only about three months old. That makes ongoing maintenance uncertain for a package still at v0.2.
The package is only 104 days old and has two releases, both published within the first day. This provides little evidence of an established release process.
The repository uses Composer build tooling, which fits the package ecosystem. No security scanning tools are present, a modest transparency and maintenance gap.
The repository has no security policy. This weakens the project's stated process for handling vulnerabilities, although it is not evidence that the package is unsafe.
The latest release is v0.2 and is not a stable major version, so the API may still change substantially. It is not marked as a prerelease, which provides limited compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0|^3.0 | — | — |
saloonphp/saloon Version ^3.0|^4.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
saloonphp/pagination-plugin Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.