Usable with caveats: it is actively released, clearly backed by an organization, and not deprecated or archived. The package is very young and recent repository activity is concentrated in one contributor, so maintenance continuity is not yet well established.
70%
Total Score
67
100
81
88
The package is only 37 days old but has had 53 releases, including a release within minutes of collection, showing strong current activity. Its short history still provides limited evidence of long-term maintenance.
All observed recent commits came from one contributor, creating a thin operational base. Organizational ownership provides some handoff potential, but no second active contributor was observed.
Only one commit from one active maintainer was observed in the last three months. The repository is very young, but the limited recent activity leaves maintenance continuity uncertain.
Composer is used as a build tool, but no security scanning tooling was detected. The missing scanning is a transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This matters for a server-side framework component, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
symfony/type-info Version ^7.0 || ^8.0 | — | — |
illuminate/routing Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/filesystem Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.