Usable with caveats: it is actively developed, clearly packaged, tested in the repository, and not deprecated or archived. The project is only 30 days old and all recent commits come from one maintainer, while its workflow does not declare token permissions.
72%
Total Score
70
100
83
90
Registry publishing access is held by one maintainer. This is a real continuity concern for a user-owned project, although repository activity shows that maintainer is currently active.
The registry namespace and repository are owned by the same individual account, so the package has direct ownership alignment but no organization backing to mitigate its single-maintainer risk.
The package is only 30 days old with three releases and a median interval of about 3 days, so it shows active early development but has limited maturity and long-term track record.
One contributor made all 45 recent commits, leaving no demonstrated backup maintainer and creating a meaningful continuity risk for a young project.
Seven stars and no forks indicate limited external adoption. This is supporting evidence of low maturity, not a decisive problem for a small specialized tool.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.