The MIT declaration, matching repository, and straightforward Composer dependency profile are reassuring. Minimal documentation and the lack of security tooling leave maintenance and verification less transparent.
58%
Total Score
50
100
70
83
The package includes a README and release notes for this version, but the README is only 13 characters and provides no usage guidance. Missing tests and a changelog are normal for a published artifact and are not concerns here.
The repository is owned by an individual rather than an organization, so there is no visible organizational backing to compensate for the single-release history.
The package has only one release, published about 16 months ago, with no releases in the last 12 months; this provides little evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest verification gap for a package with little release history.
The repository has no security policy, which reduces transparency about how vulnerabilities are reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.