The compact package has clear installation guidance and matching source, while its small maintainer footprint and missing security process add upkeep risk. Its dependencies are limited and the project is not archived.
60%
Total Score
67
100
83
83
Only one account has registry publish access, which creates a thin publishing base. The organization-owned repository provides some backing, so this is a caution rather than a severe risk.
The package is 762 days old with six releases, but only one release in the last 12 months; this suggests a slower maintenance pace despite the recent v1.1.4 publication.
There were zero commits and zero active maintainers in the last three months, a concrete sign that active maintenance may have slowed.
The repository has one star, zero forks, and two watchers, showing very limited public adoption. Popularity is only supporting evidence, but this modestly reduces confidence in project maturity.
The repository uses Composer, but no security scanning tools are configured. This leaves security and dependency hygiene less visibly monitored.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0|^7.0 | — | — |
illuminate/support Version ^6.20|^8.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.