This is a generally healthy and usable release: it has a long release history, a stable non-prerelease version, a current release, an unarchived organization-backed repository, clear MIT licensing, and repository tests and documentation that compensate for their absence from the artifact. The main concern is that the repository recorded no commits and no active maintainers in the last 3 months, despite a recent release and push, while the project has very low popularity and no security-scanning tooling; these warrant monitoring but do not by themselves make the package unfit to depend on.
78%
Total Score
88
100
89
100
The repository recorded zero commits and zero active maintainers during the last 3 months. This suggests a possible slowdown or release-only maintenance pattern, although the recent release and push provide partial compensation.
The repository has only 1 star, 4 forks, and 1 watcher, indicating limited external adoption or review. Popularity is supporting evidence rather than a decisive health verdict, so this is a caution rather than a severe risk.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a transparency and defense-in-depth gap, not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.0 | — | — |
lcobucci/jwt Version ^3.4 || ^4.0 | — | — |
guzzlehttp/guzzle Version ^6.4 || ^7.1 | — | — |
composer/ca-bundle Version ^1.2 | — | — |
illuminate/collections Version ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.