This is a usable but very young package with encouraging signs of active development: it has 9 stable releases in 35 days, was pushed recently, is not deprecated or archived, has a focused dependency profile, and is backed by an organization-owned repository that matches the package and mentions it in the README. However, the package has no tests or changelog, all 10 recent commits come from one contributor, the repository has no security scanning or security policy, and it has no demonstrated adoption through stars or forks. The rapid release cadence is positive for activity but does not yet establish maturity, so depend on it with normal caution and consider reviewing changes closely until its testing and contributor base develop.
68%
Total Score
88
100
78
90
A substantial README documents installation and usage, but neither the artifact nor repository contains tests or a changelog. For a young framework integration, the missing validation and release documentation are meaningful transparency and maintenance gaps.
Nine releases in the last 35 days, with a median interval of about 0.4 days, demonstrate active publishing but also reflect a very short history that provides little evidence of long-term stability.
One contributor made all 10 commits in the last 3 months, creating a concentrated maintenance dependency. Organization backing partly mitigates handoff risk, but no second active contributor is shown.
The repository has zero stars, forks, and watchers. This does not establish a defect, but it provides no external adoption or community validation for this newly released package.
Composer build tooling is present, but no security scanning tools are configured. The build setup is appropriate, while the missing security automation is a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lara-igniter/enum Version ^1.0 | — | — |
lara-igniter/framework Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.