The repository includes tests, release notes document this version, and Dependabot is enabled. Workflow permissions and unpinned actions need care, while recent work comes from one contributor.
64%
Total Score
67
94
50
The package runs a post-autoload-dump install-time script. Composer lifecycle execution is not inherently unsafe, but it adds an execution step that deserves review when installing the dependency.
All three recent commits came from one contributor. The organization-owned project provides some handoff capacity, but no second recent contributor is shown to reduce dependence on that person.
The repository recorded three commits in the last three months, showing recent activity, but the pace is modest for an actively evolving library.
The repository has no published security policy. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself show abandonment.
This is a non-prerelease v0.5.0, which is more stable than an explicitly pre-release version, but the package has not reached a stable major version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
honed/core Version ^0.55.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.