The repository is active and the latest release includes PHP 8.4 compatibility, but only one commit from one contributor appeared in the last three months. Organization backing helps offset the concentrated activity, while the lack of a security policy leaves a transparency gap.
67%
Total Score
67
100
83
83
The package has existed since October 2022 and released once in the last 12 months, indicating slow but continuing maintenance rather than abandonment.
All recent commits came from one contributor, creating a narrow bus factor; the organization-owned repository provides some capacity to hand maintenance off.
Only one commit from one active maintainer was recorded in the last three months, which is a meaningful sign of limited maintenance capacity.
The repository has no stars, forks, or watchers, offering no community adoption evidence; this is supporting context rather than a standalone health verdict.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security coverage unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.4 | — | — |
guzzlehttp/guzzle Version ^7 | — | — |
illuminate/support Version ^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.