This is a healthy, actively maintained early-stage package with a stable v1.1.0 release, a matching repository, clear documentation, an MIT license, repository tests, security policy, Dependabot, and recent activity from two contributors. Its main limitations are its short 76-day history, only three releases, very small adoption footprint, and incomplete explicit GitHub Actions token permissions; these warrant routine review but do not currently make the package unfit to depend on.
84%
Total Score
80
100
89
90
Only one account has registry publishing access, which limits publishing redundancy; however, repository activity shows a second active contributor, partially mitigating the operational concern.
The repository is owned by an individual account rather than an organization, so maintenance depends more directly on the identified contributors; current two-contributor activity provides some resilience.
The package is only 76 days old with three releases and a median release interval of about 38 days, so its maintenance track record is still limited despite regular releases.
The repository has only 1 star, 0 forks, and 1 watcher, indicating minimal public adoption; this is supporting caution rather than a decisive health problem for a small package.
Two workflows omit top-level permissions and one declares top-level write access, leaving GitHub Actions privilege boundaries less explicit than ideal even though no dangerous workflow pattern was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.10 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.