The repository includes a substantial test suite and the package is MIT-licensed, with no install scripts. Its single maintainer, absent security policy, and zero commits in three months leave maintenance capacity uncertain.
61%
Total Score
50
88
75
Only one registry account has publish access, and the repository is owned by an individual rather than an organization. This leaves limited visible publishing redundancy.
The package has existed since August 2020 and has 27 releases, but only one release in the last 12 months. That suggests slowing maintenance without indicating abandonment by itself.
There were zero commits and zero active maintainers in the last three months. The recent release push is compensating evidence, but the lack of ongoing commit activity still raises maintenance concerns.
The repository uses Composer for builds, but no security-scanning tools were detected. This is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving no documented channel or process for handling vulnerability reports.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=5.6 | — | — |
facade/ignition-contracts Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.