A long-running stable package has a clear license, matching repository, and release notes. Its single maintainer, no commits in three months, absent security scanning, and unpinned workflow actions reduce confidence in ongoing support.
68%
Total Score
63
100
94
67
Only one account has registry publish access, leaving limited publishing redundancy. The matching personal repository provides some backing, but does not remove the single-maintainer dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Although a release was published recently, the lack of ongoing development lowers confidence in future fixes.
There are no open issues or pull requests, and no activity in the last month. This may reflect a quiet project, but it provides little evidence of active support.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
krowinski/php-mysql-replication Version ^8.0 || ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.