The repository has no security policy or automated security scanning, and its sole workflow uses an unpinned action. Licensing, README coverage, release notes, and installation behavior are otherwise solid, but the project has little public adoption.
58%
Total Score
50
100
83
75
The repository is owned by an individual user rather than an organization, so the small maintainer base does not have visible organizational backing to compensate for the limited activity.
The package has 25 releases but none in the last 12 months; its latest registry release was in September 2024. This weakens confidence in ongoing release maintenance despite the established history.
There were no commits and no active maintainers during the last three months. The recent repository push partly offsets abandonment concerns, but it does not restore confidence in regular release development.
The repository has only 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little independent validation or community backing.
Composer build tooling is present, but no security-scanning tools were detected. For a framework with many runtime dependencies, that is a meaningful maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/once Version * | — | — |
nesbot/carbon Version ^2.72.2|^3.0 | — | — |
illuminate/bus Version * | — | — |
illuminate/log Version * | — | — |
illuminate/auth Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.