The package includes a substantial README, tests, and a small source tree, with no install-time scripts. Its repository is active and identifies the package, but the project has limited operational history and no published security policy.
61%
Total Score
69
75
The manifest declares a proprietary license, so the release is licensed but does not provide the rights normally expected from an open-source dependency. No license file is present to clarify those terms.
This package is only 44 days old and has one release, so there is not yet enough release history to demonstrate sustained maintenance or compatibility practices.
The repository has zero stars, forks, and watchers. Because the package is only 44 days old, this is weak supporting evidence rather than a standalone health verdict.
Composer is used for builds, but no security-scanning tooling is reported. That leaves a transparency and maintenance gap without proving the package is unsafe.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities. This is a real transparency gap, although it is not evidence of a vulnerability.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
g-efac/sdk Version ^0.2 | — | — |
guzzlehttp/psr7 Version ^2.7 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
illuminate/support Version ^12.0 | — | — |
illuminate/contracts Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.