The MIT license, matching repository, and README make integration clearer. The small codebase has no tests or security policy, and about two years without activity leaves maintenance uncertain.
57%
Total Score
50
86
75
The package has 7 releases, but none in the last 12 months and its latest release was about two years ago. This is a meaningful maintenance concern, though the prior release cadence was reasonably regular.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap. No newer activity is provided to offset the maintenance concern.
Composer build tooling is present, but no security-scanning tools are configured. That limits automated supply-chain and vulnerability checks, although it is not evidence of a defect by itself.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a transparency gap for a package used in applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0|^7.0 | — | — |
illuminate/support Version ^6.20|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.