The package is small and clearly documented, with a matching repository and release notes. A single maintainer, no tests, and no security policy make ongoing support harder to verify.
58%
Total Score
50
100
88
83
Only one registry maintainer is listed. Because the repository is user-owned rather than organization-backed, this leaves limited visible publishing redundancy.
The package and repository are both tied to the same individual user account, with no organization backing shown. This is consistent and transparent but provides limited visible continuity.
This is a young package with one release, published 175 days ago, so there is not enough release history to demonstrate sustained maintenance.
The repository has no commits and no active maintainers in the last 3 months. For a package only 175 days old, this leaves its maintenance trajectory unproven.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest source-maintenance and verification gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.