Usable with caveats: the release is current, well documented, tested, licensed, and backed by an active repository. However, only three releases exist and there were no commits or active maintainers in the last three months, so ongoing maintenance capacity is not yet well established.
72%
Total Score
67
100
83
83
The repository owner is a user account rather than an organization, so the single registry maintainer represents a genuinely narrow ownership base rather than normal organization publishing hygiene.
The package is 408 days old but has only three releases, with one release in the last 12 months and a median interval of about 204 days. This indicates a relatively slow release cadence, although the latest release is current.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release and push provide some compensation, but current maintenance activity remains thin.
The repository has 8 stars, 1 fork, and 1 watcher. This is limited adoption evidence, but popularity is supporting context rather than a decisive health measure.
Composer build tooling is present, but no security scanning tools were detected. The strong tests and documented security policy partly offset this, but automated security coverage is not evident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 | — | — |
nesbot/carbon Version ^3.10 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.