The project is young and has only one active contributor, so maintenance depends heavily on one person. Documentation, licensing, and a security policy are present, while the small dependency set and no install scripts reduce operational risk.
68%
Total Score
67
100
94
100
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not compensated by visible organizational backing.
All 9 commits in the last 3 months came from one contributor, giving the project a single-maintainer bus factor. This creates a meaningful continuity risk for a young package.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not evidence of a defect by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
gurento/kafka-consumer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.