The project has a clear README, tests, MIT licensing, and recent commits. Maintenance depends heavily on one contributor, and the repository has no security policy; the install-time script also merits review.
68%
Total Score
75
100
67
A post-autoload-dump install-time script runs during Composer installation, increasing installation complexity and warranting review even though this signal alone does not show harmful behavior.
One contributor made 27 of 28 recent commits, leaving maintenance highly concentrated despite a second contributor being active.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
guzzlehttp/guzzle Version ^7.8|^8.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.