Tests, a recognized license, and release notes provide useful transparency. The pre-1.0 version and unpinned workflow actions add maintenance and build-integrity concerns; pin this version only if its unfinished status fits your needs.
57%
Total Score
50
70
50
The package has existed since November 2019 and has nine releases, but only one release arrived in the last 12 months with a median interval of about 246 days. That indicates a slow, limited release cadence.
The repository recorded zero commits and zero active maintainers in the last three months. Although the latest release was recent, the observed short-term activity provides weak evidence of ongoing maintenance.
The repository uses Composer for its build, which fits the package ecosystem, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The linked repository has no security policy. This does not show a vulnerability, but it leaves the process for reporting and handling security issues unclear.
Version v0.7.1 is not a prerelease, but the package remains below 1.0. Consumers should expect a less mature compatibility promise than with a stable major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/container Version ^10.0|^11.0|^12.0|^13.0 | — | — |
friendsofphp/php-cs-fixer Version ^3.75 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.