The package includes tests, a changelog, a clear license, and a focused dependency set. Its small audience, missing security policy, quiet recent development, and unpinned workflow actions leave maintenance and build-integrity concerns.
67%
Total Score
50
100
89
83
Only one registry account can publish releases. This is a real continuity risk for a user-owned project because a single publisher provides little redundancy if maintenance stops.
The repository and registry are owned by the same individual account rather than an organization. That matches the single-maintainer profile but provides no organizational continuity buffer.
There were no commits and no active maintainers in the last three months. Although a release occurred recently, the lack of follow-up development lowers confidence in ongoing maintenance.
The repository has one star, no forks, and no watchers. Popularity is not required for a small package, but these counts provide little external evidence of adoption or community support.
Composer build tooling is present, but no security scanning tools were detected. The missing automated security checks are a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.