The repository includes tests and a changelog, and the package has a clear MIT license with few runtime dependencies. A single maintainer, no security policy, and two unpinned workflow actions reduce confidence in long-term upkeep and build hygiene.
60%
Total Score
50
100
89
67
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful maintenance and abandonment concern for a young package.
Only one registry publisher account is listed, and the repository is user-owned rather than organization-backed, leaving a thin apparent maintainer base.
The repository owner is an individual user account rather than an organization, so there is no observed organizational backing to offset the thin maintainer base.
Five releases arrived over about six days, with a median interval of about 22 hours, showing active initial development but little evidence of a sustained cadence.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.