A README, repository test suite, and MIT licensing make the package easier to evaluate. One maintainer, no security policy, and unpinned workflow actions add resilience and build-hygiene concerns.
40%
Total Score
33
100
81
83
The package has 57 releases over more than 10 years, but its latest release was in February 2022 and there were no releases in the following four years and seven months. That long release gap is a substantial maintenance concern.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the last release being in February 2022, this points to sustained inactivity rather than a short pause.
Only one registry maintainer account is listed. Because the repository is user-owned rather than organization-backed, this indicates limited publishing redundancy and increases continuity risk.
The registry namespace and repository are both owned by the same individual account, so the source ownership is consistent but does not show organizational backing or additional continuity capacity.
Composer is used for builds, but no security scanning tools are reported. The missing scanning is a modest transparency and maintenance gap, not a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.10 | — | — |
illuminate/support Version ^6.0||^7.0||^8.0||^9.0 | — | — |
illuminate/container Version ^6.0||^7.0||^8.0||^9.0 | — | — |
pulkitjalan/google-apiclient Version ^4.1||^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.