The README clearly documents installation, usage, requirements, and licensing, while the package has a small, focused dependency set and no install-time scripts. The lack of security scanning and the very small project footprint leave limited evidence of long-term resilience.
58%
Total Score
50
100
81
100
The package is only 124 days old and has two releases published within hours of each other, so there is little evidence of a sustained release cadence yet.
The repository recorded zero commits and zero active maintainers over the last 3 months. Given the package's recent creation, this is meaningful evidence of stalled maintenance rather than a mature steady state.
Composer build tooling is present, but no security-scanning tools were detected. That reduces transparency around automated checks, although it is not by itself evidence of an unsafe release.
Version v0.2.0 is not a prerelease, but the package remains below major version 1 and has limited release history, indicating a still-maturing API.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orchid/platform Version ^14.15 | — | — |
van-ons/laraberg Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.