Its README, MIT declaration, small dependency surface, and lack of install-time scripts make adoption straightforward. The project is young, so longer-term resilience remains unproven.
65%
Total Score
67
100
89
75
The artifact includes a substantial README, and the repository uses GitHub Releases, but it has no tests or changelog. Missing tests reduce confidence for a business-rules library, while the absent changelog is not a packaging gap.
The repository is owned by the same individual as the registry namespace, and the owner type is User rather than Organization. This confirms direct ownership but provides no organizational maintenance redundancy.
One contributor made all 13 commits in the last 3 months, giving the project a single-maintainer bus factor. That concentration creates a meaningful continuity risk for a young library.
Composer is used as the build tool, but no security-scanning tool is configured. The build setup is appropriate, while the missing scanning coverage is a modest transparency gap.
The repository has no security policy. For a business-rules library this is a transparency and incident-reporting gap, although it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.