The MIT license, detailed README, release notes, and organization-backed repository provide useful transparency. No security policy or automated security scanning leaves safeguards and long-term maintenance visibility limited.
60%
Total Score
83
100
81
88
There were four releases within roughly nine hours on the first release day, but no later release is shown across the package's 287-day age; this suggests an unproven maintenance cadence.
The repository had zero commits and zero active maintainers in the last three months; combined with the launch-day-only push, this is a meaningful maintenance concern.
Composer build tooling is present, but no security scanning tools were detected, leaving a notable project-safeguard gap.
The linked repository is not archived, although its last push was on the initial release day and therefore does not offset the lack of recent activity.
The repository has no security policy, so users have no documented security reporting path in the collected evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^9.0|^10.0|^11.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.