This is a usable but very new package with good basic transparency: it has an MIT declaration, a substantial README, tests in both the artifact and repository, a coherent file tree, and no install-time lifecycle scripts or dangerous workflows. However, v1.0.2 is the only release and the package is 0 days old, so there is no demonstrated maintenance history; repository activity and popularity are also currently zero, and the project has only one registry maintainer. The absence of security scanning and a security policy adds a smaller hygiene concern. Adoption is reasonable for evaluation or controlled use, but the package should be monitored closely before becoming a critical dependency.
62%
Total Score
50
100
83
90
Only one account has registry publish access. This is not evidence of unsafe administration by itself, but it indicates a thin publishing base and limited continuity if the maintainer becomes inactive.
The repository is owned by an individual user rather than an organization, so institutional backing is not demonstrated; this reinforces the continuity concern alongside the single maintainer and zero activity.
The package is 0 days old with only one release, so it has no demonstrated release track record or maintenance history; this is a meaningful maturity concern.
There were 0 commits and 0 active maintainers in the last 3 months. The package's 0-day age explains this result, but it still leaves maintenance capacity unproven.
There are no issues or pull requests and no activity in the last month; given the repository's 0-day age this is inconclusive rather than severe, but it does not demonstrate an active support community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/notifications Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.