Usable with caveats: it is an actively released, organization-backed component with a clear license and a recent repository push. However, no commits or active maintainers were recorded in the last three months, and the repository has no security policy, so verify ongoing maintenance before adopting it broadly.
72%
Total Score
75
100
89
83
No commits and no active maintainers were recorded during the last three months. This conflicts with the recent repository push and release history, but still creates a meaningful concern about current maintenance continuity.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, so these low counts modestly reduce external validation but do not establish that the package is unhealthy.
Composer is used as the build tool, but no security scanning tools were detected. For a small PHP component this is a transparency gap rather than a severe risk.
No security policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10|^11|^12|^13 | — | — |
moonshine/contracts Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.