Usable with caveats: the release is well documented, tested, licensed, and actively published, but the project has only two releases and no commits in the last three months. Its small audience and limited security tooling make it less proven for critical dependencies.
68%
Total Score
63
100
83
90
One registry publishing account is present. Because the repository is owned by the same individual rather than an organization, the single-person maintainer base leaves limited redundancy if that maintainer becomes unavailable.
The registry namespace and repository owner match, but both are associated with an individual account rather than an organization. The matching ownership supports authenticity, while the lack of organizational backing limits continuity.
Only two releases have been published across roughly 14 months, with one release in the last 12 months. That is limited evidence of sustained maintenance and release maturity.
The repository recorded zero commits and zero active maintainers during the last three months. Although v1.4.0 was recently released, this short-term inactivity is a meaningful maintenance concern.
The repository has 8 stars, 0 forks, and 1 watcher. This is a small user base and offers little external validation, though popularity is supporting evidence rather than a health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3|^8.0 | — | — |
nesbot/carbon Version ^3.10 | — | — |
illuminate/support Version ^12.19|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.