The package has a clear README, matching source repository, release notes, and MIT licensing. Long-term support is uncertain because registry releases stopped in 2019 and recent repository activity is absent. Its small user and maintainer base adds to the adoption risk.
58%
Total Score
50
50
83
50
The package declares 10 runtime dependencies and no development dependencies, creating a relatively broad dependency surface for a small command-line integration package. The signal does not show a direct dependency failure or known obsolete dependency.
A post-root-package-install Composer script is present. This is an install-time behavior worth awareness, but the provided signal does not show that it is harmful or unusually broad.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is little visible publishing redundancy.
The registry namespace and repository are tied to the same individual user account, with no organization backing shown. This is consistent ownership but provides limited continuity if that maintainer stops contributing.
The package has only 4 releases, with no release in the last 12 months and the latest release in July 2019. The repository was pushed in January 2025, which provides some compensating evidence but does not show continued release maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mockery/mockery Version ^1.0 | — | — |
vlucas/phpdotenv Version ^3.3 | — | — |
illuminate/config Version 5.8.* | — | — |
illuminate/events Version 5.8.* | — | — |
illuminate/console Version 5.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.