The project has solid documentation, tests, release notes, licensing, and recent commits. Its single-release history, one-person maintenance base, and seven unpinned workflow actions leave more dependence risk than a mature package.
67%
Total Score
63
100
83
83
The package runs a post-autoload-dump install lifecycle script. This is an additional install-time execution surface, although the signal does not show that the script is dangerous.
The repository is owned by the Modularavel user account rather than an organization, so the single-contributor maintenance concentration is not visibly offset by organizational backing.
This package is only 51 days old and has one release, so there is not yet enough release history to establish long-term maintenance stability.
All 10 commits in the last three months came from one contributor, so maintenance depends entirely on a single active person.
There are three open pull requests and no new issues or merged pull requests in the last month. The open work shows some activity, but the lack of recent merges limits evidence of completed maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.