The package includes a substantial README, tests, and security scanning tools, with no install-time scripts. It is not deprecated or archived, but its solo ownership and lack of recent activity leave maintenance uncertain.
61%
Total Score
50
100
94
83
Only one registry maintainer is listed. Because the repository is user-owned rather than organization-owned, this thin publishing base adds some continuity risk.
Six releases were published during the first 202 days, but the latest release was about six months ago. The early burst shows initial activity, while the subsequent pause raises maintenance concern.
No repository security policy is present. This is a transparency gap, but it is secondary to the stronger maintenance signals and does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.6 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
illuminate/config Version ^12.52 | — | — |
illuminate/support Version ^12.52 | — | — |
illuminate/container Version ^12.52 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.