Usable with caveats: the repository is active, documented, tested, and not archived or deprecated. However, it is only 30 days old, all recent commits come from one contributor, and its release cadence is unusually rapid.
72%
Total Score
70
100
88
90
Only one registry account has publishing access, which is a limited publishing base; the repository's active commit history provides some compensation but does not remove the continuity risk.
The package and repository are owned by the same individual account rather than an organization, so the concentrated maintainer activity represents a genuine single-owner continuity risk.
The package is only 30 days old but already has 39 releases, with a median interval of about 29 minutes; this shows active development but an unusually rapid cadence that may increase release churn.
One contributor made 100% of the 209 commits in the last three months, creating a meaningful single-maintainer continuity risk despite the high activity level.
Composer build tooling is present, but no security scanning tool was detected; the missing scanner is a transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5.1 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.