The MIT license, repository tests, changelog, and Dependabot provide useful baseline transparency. Its single maintainer and seven runtime dependencies offer limited evidence of maturity beyond this initial release.
48%
Total Score
50
50
50
A `post-autoload-dump` install-time script is present. This is common Composer behavior, but it adds execution during installation and merits review when adopting a new package.
Only one registry publishing account is listed. The repository is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer stops maintaining the package.
The artifact includes a README and changelog, and the repository has tests, but the README still contains unfilled scaffold placeholders such as `:package_description` and `:vendor_slug`, weakening consumer documentation.
This is the package’s only release, published about 201 days ago, so there is no release track record yet and maintenance cannot be judged from version history.
The repository recorded zero commits and zero active maintainers in the last three months, despite a push about five months after the release; this is weak evidence of ongoing maintenance for a new package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/mail Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.