Its 0.x status and lack of repository security scanning limit confidence, although the release is well documented with tests, a changelog, and exact release notes. The small project has no recorded commits in the measured period, so longer-term maintenance remains unproven.
64%
Total Score
50
100
79
67
Four releases were published over about 19 days, but the median interval is only about 9 minutes and the package is only about four months old. This shows initial activity but not an established release pattern.
No commits and no active maintainers were recorded in the last three months. Because the package is young and the repository was updated for the assessed release, this is a maintenance concern rather than evidence of definite abandonment.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful repository hygiene gap for a package intended to be used as a dependency.
The repository has no SECURITY.md or other security policy. This weakens vulnerability-reporting transparency, though it does not by itself show unsafe code.
Version v0.1.0 is a non-stable-major release, so its API and behavior may still change. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72 || ^3.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/collections Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.