The package is licensed, documented, tested in the repository, and has no install-time scripts. A single maintainer and missing security policy leave less resilience if maintenance stops.
68%
Total Score
50
100
100
83
Only one registry account, Karson Adam, has publishing access. The active release history helps, but a single publisher leaves limited redundancy if that maintainer becomes unavailable.
The repository is owned by an individual user rather than an organization, so there is no observed organizational backing to compensate for the thin maintainer base.
The repository recorded zero commits and zero active maintainers in the last three months. Frequent registry releases provide some counterevidence, but the lack of recent source activity is a real maintenance concern.
The repository has no security policy file. Dependabot is enabled, which provides some automated dependency monitoring, but it does not replace a documented vulnerability-reporting process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.