Usable with caveats: the release is licensed, documented, tested, actively released, and backed by a matching repository. The main concerns are no commits in the last three months, a single registry maintainer, and missing automated security scanning.
72%
Total Score
63
50
89
88
The package has five runtime dependencies, including Laravel components and Symfony YAML. This is a meaningful dependency surface but not unusually large for a Laravel security package.
Only one account has registry publishing access. That is a limited publishing base for continuity, although the repository is user-owned and the project shows recent release and pull-request activity.
The registry namespace and repository owner both identify Grazulex, with the repository owned by a user rather than an organization. This is consistent backing, but offers less organizational continuity evidence.
There were zero commits and zero active maintainers in the last three months. The recent release and three merged pull requests provide some compensation, but the lack of direct commit activity is a real maintenance warning.
The repository has 12 stars, no forks, and one watcher. This is limited adoption evidence, but popularity is supporting evidence rather than a health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3|^8.0 | — | — |
nesbot/carbon Version ^3.10 | — | — |
illuminate/support Version ^12.19|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.