The package includes tests, release notes, a clear README, and a matching source repository. MIT licensing and two runtime dependencies keep integration straightforward.
68%
Total Score
50
100
88
67
The package declares a post-autoload-dump install-time script. Such scripts add installation behavior to review, but this signal alone is not a severe health concern.
The registry lists one maintainer. That is a thin publishing base, and the lack of recent repository activity provides no compensating evidence of broader maintenance capacity.
The package has only two releases across about 32 months, with one release in the last 12 months and a median interval of about 668 days; this suggests a slow maintenance cadence.
The repository recorded no commits and no active maintainers in the last three months, despite the latest release being the main evidence of recent activity; this weakens confidence in ongoing maintenance.
The repository uses Composer but reports no security scanning tools. That is a modest hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.