The package has a clear README, changelog, tests in the repository, an MIT license, and organization backing. Its limited release history, no commits in the last three months, and broad unpinned workflow actions reduce confidence in ongoing maintenance and build reproducibility.
68%
Total Score
75
100
89
63
A post-autoload-dump install-time script is present. This is worth awareness for dependency installation, but the signal alone does not show harmful or unusual behavior.
This package is 111 days old and has only one release, so there is little release history from which to judge long-term maintenance.
The repository recorded zero commits and zero active maintainers over the last three months. For a package only 111 days old, this leaves a thin record of ongoing maintenance.
There are no new or closed issues in the last month and two open pull requests, showing limited visible collaboration activity without proving abandonment.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers maturity confidence modestly but does not determine fitness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0||^12.0||^13.0 | — | — |
php-http/discovery Version ^1.19.3 | — | — |
sentdm/sent-dm-php Version ^0.23 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
illuminate/notifications Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.