MIT licensing, tests, and a matching repository make the package transparent enough to inspect. Its workflows leave all six actions unpinned and the repository has no security policy, so maintenance and build hygiene deserve extra scrutiny.
55%
Total Score
50
71
75
The package includes tests and a GitHub release with notes for this version, which supports basic project transparency. The very short README is a minor consumer-documentation gap.
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not have organizational backing to offset the thin maintenance base.
The package has only one release, with no releases in the past three years, which is a meaningful maintenance concern. Recent repository activity provides some compensation but does not establish a dependable release cadence.
There were no commits or active maintainers in the last three months, which weakens evidence of ongoing maintenance. The recent repository push is a limited counter-signal but does not show sustained development.
Composer build tooling is present, but no security scanning tools were detected. For a package handling API integrations, that leaves a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9|^10.0 | — | — |
illuminate/contracts Version ^9|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.