The package is clearly documented and licensed, with tests and organization backing. Recent maintenance is quiet, and no security policy or scanning is present; the install-time script also deserves attention.
62%
Total Score
75
88
50
A post-autoload-dump Composer script runs during installation, adding execution behavior that developers should understand before adopting the package.
The package has 103 releases over about 2 years, but only 3 releases in the last 12 months despite a historically short median interval of about 4 days, indicating a noticeable slowdown.
The repository recorded zero commits and zero active maintainers in the last 3 months, a meaningful sign of currently low maintenance capacity. The recent release provides some counterevidence but does not show ongoing development.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so there is no documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version ^2.0 | — | — |
illuminate/support Version ^10|^11|^12|^13 | — | — |
illuminate/database Version ^10|^11|^12|^13 | — | — |
illuminate/collections Version ^10|^11|^12|^13 | — | — |
encoredigitalgroup/stdlib Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.