The project is very new, with only two releases and no recorded commits over the past three months. Its documentation, licensing, tests in the repository, security policy, and dependency scanning provide useful safeguards, but every workflow action is unpinned and two workflows grant broad write access.
68%
Total Score
63
100
83
67
The package runs post-autoload-dump, post-install-cmd, and post-update-cmd scripts, which add install-time behavior and therefore modest dependency-onboarding risk.
One registry maintainer publishes the package. Because the repository is user-owned rather than organization-backed, this represents a thin publishing base and limited visible redundancy.
The package and repository are owned by the same individual account, so the source appears correctly aligned, but there is no organization backing shown to provide additional continuity.
This is a very new package, first released about one day ago, with only two releases. That leaves little evidence of sustained maintenance or release stability.
The repository records zero commits and zero active maintainers in the past three months, but the project is only about one day old and was recently pushed. This is insufficient history rather than clear abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.