Documentation and tests make integration clearer, while the stable release and matching repository add confidence. The small maintainer base, absent recent commits, and missing security policy leave meaningful maintenance risk.
64%
Total Score
50
100
88
50
Only one registry account has publish access, creating concentration risk; this is partly consistent with the repository being owned by an individual rather than an organization.
The repository owner is a user account rather than an organization, so there is no demonstrated organizational backing to offset the single-maintainer risk.
The package has 17 releases over about 6 years, but none in the last 12 months; this indicates a meaningful slowdown despite an established release history.
There were zero commits and zero active maintainers in the last 3 months, consistent with the absence of recent releases and raising maintenance risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.35|^2.0|^3.0 | — | — |
guzzlehttp/guzzle Version ^6.5|7.* | — | — |
illuminate/support Version * | — | — |
illuminate/container Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.