Documentation, licensing, testing, and repository controls are in place. The project is brand new, with no demonstrated commit or release track record, and installation runs a post-autoload script.
65%
Total Score
67
100
88
83
A post-autoload-dump Composer lifecycle script runs during installation, adding execution behavior that consumers should understand before adoption.
The registry lists one maintainer, which limits visible publishing redundancy. Organization backing and the matching repository provide some compensation.
The package is 0 days old with only one release, so there is no release track record to establish maintenance reliability. Its stable 1.0.0 version is a small positive but cannot offset the lack of history.
There were no commits and no active maintainers in the previous three months, but the repository and package were created on the same day, so this mainly indicates no established history rather than a demonstrated collapse.
The repository has zero stars, forks, and watchers. For a package released 0 days ago this is expected and weak evidence, but it provides no external maturity signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.