Usable with caveats: it has clear licensing, documentation, tests in the repository, and organization-backed source that matches the package. However, this is the first release with no demonstrated maintenance history, and its workflow lacks explicit token permissions and security scanning.
68%
Total Score
75
79
63
A post-autoload-dump install-time script runs during dependency setup. The signal does not show that it is harmful, but lifecycle execution adds a maintenance and review consideration.
This is the first release and was published only hours ago, so there is no release track record or evidence of sustained maintenance yet.
The repository has no commits or active maintainers recorded in the last three months, although the repository was created or pushed only hours before this assessment, so this mainly reflects the package's extreme newness.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap in the source project.
No repository security policy is present, reducing transparency about how vulnerability reports would be handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0|^7.0|^8.0 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/cache Version ^11.0|^12.0|^13.0 | — | — |
league/commonmark Version ^2.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.