The package is clearly licensed, well documented, and backed by an organization with repository tests and security tooling. Its small dependency set and matching source repository help, but the project has gone about 18 months without a registry release and its workflows use broad permissions and unpinned actions.
58%
Total Score
63
100
83
75
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the long registry release gap, this is meaningful evidence of stalled maintenance.
The package runs a post-autoload-dump install-time script. This is a supply-chain exposure that deserves review, although the signal gives no evidence that the script performs harmful actions.
The package has seven releases over about two years, but no registry release in roughly 18 months. That prolonged release gap lowers confidence in ongoing maintenance.
There are no open issues and five open pull requests, but no pull requests were merged in the last month, suggesting limited recent throughput.
Seven stars and no forks show limited adoption, but popularity is supporting evidence and does not outweigh the stronger maintenance and transparency signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/contracts Version ^10.0||^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.