The source matches the package, includes focused tests, and publishes release notes for this version. MIT licensing, no install-time scripts, and an unarchived repository improve adoption confidence.
64%
Total Score
50
83
67
This is a 105-day-old package with only one release, so there is little evidence of sustained maintenance or release maturity. Its recent launch explains some of that limitation but does not remove the coverage gap.
There were 0 commits and 0 active maintainers in the last 3 months, leaving no evidence of ongoing maintenance after the initial release. Because the package is only 105 days old, this is concerning but not yet proof of abandonment.
The repository has only 2 stars, no forks, and no watchers, indicating limited external adoption or review. Low popularity is supporting caution rather than evidence that the package is unsafe to use.
The repository uses Composer but reports no security-scanning tools, so automated detection coverage is limited. The build tooling itself is appropriate for a PHP package.
No security policy is present, reducing transparency about how vulnerabilities should be reported and handled. This is a maintenance and disclosure gap, not a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.