The package has a clear MIT license, a substantial README, stable versioning, and an organization-backed repository. Its small public footprint and limited release history leave less evidence of long-term maintenance.
60%
Total Score
75
100
83
83
The package has only 2 releases over roughly 11 months, with the latest release about 10 months ago. This is limited evidence of sustained maintenance, though the project is still relatively young.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with the short release history, this weakens evidence of ongoing maintenance.
The repository has 0 stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but this provides little external evidence of maturity.
The repository uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance-hygiene gap, not evidence that the package is unsafe.
No repository security policy was found. For a package that handles bot integrations, this reduces the clarity of its vulnerability-reporting process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.