Usable with caveats: it is a young package with only two releases and no recent repository activity. The matching organization-backed repository is not archived, but the package has no README, tests, or security policy, so maintenance and consumer guidance remain limited.
58%
Total Score
75
100
78
88
The package has no README, which is a meaningful consumer-guidance gap for a package with an application-style file tree. It does have a GitHub release with notes linking the v1.0.0 changes, partially improving release transparency; absent tests and changelog files are normal packaging practice and are not concerns here.
The package is about 10 months old but has only two releases, both published within the same day, providing little evidence of sustained release maintenance.
There were no commits or active maintainers in the last three months, which is the strongest evidence of currently limited maintenance capacity.
The repository has zero stars, forks, and watchers, so there is no community adoption evidence to compensate for the limited release and commit history. Popularity is supporting evidence rather than a decisive requirement for a small package.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.3 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
laravel/framework Version ^12.0 | — | — |
illuminate/database Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.