It includes tests, a useful README, and matching MIT licensing. Dependencies are few and installation has no lifecycle scripts, though the project lacks security scanning and formal security-policy documentation.
70%
Total Score
50
100
86
75
Only one registry account has publish access, and the project backing signal identifies an individual owner rather than an organization. That creates a thinner publishing and continuity base.
The repository recorded zero commits and zero active maintainers in the last three months. Although the release was recently pushed, the lack of ongoing commit activity leaves maintenance capacity uncertain.
There are two open issues and two open pull requests, but no issues or pull requests were created or merged in the last month. This suggests limited current project activity.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
The repository has no documented security policy. That reduces transparency for vulnerability reporting and response, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.