Usable with caveats: the release is well documented, tested, licensed, and actively published, but it is only 56 days old with two releases and all recent commits coming from one maintainer. The repository also lacks a security policy and explicit workflow permissions.
68%
Total Score
50
100
83
70
A post-autoload-dump install lifecycle script is present, which adds execution during installation and warrants review, though the signal does not show a dangerous script by itself.
Only one registry account has publish access, matching the user-owned repository but leaving limited publishing redundancy for a young project.
The package and repository are owned by the same individual account rather than an organization, so there is no organizational maintenance pool to offset the narrow contributor base.
The package is only 56 days old and has two releases, so its maintenance record and maturity are still limited. The short 0.2275-day median interval reflects rapid initial publishing rather than an established cadence.
All five recent commits came from one contributor, creating a high bus-factor risk for ongoing fixes and releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.63||^3.0 | — | — |
illuminate/support Version ^9.0||^10.0||^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^9.0||^10.0||^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.