The package includes extensive tests, a substantial README, Composer security scanning, and a matching source repository. Its install hook and incomplete workflow audit deserve extra scrutiny before production adoption.
62%
Total Score
67
83
50
The package runs a post-autoload-dump install-time script, adding execution during dependency installation and warranting review of that hook.
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
This is the first release, published today, so there is no track record for release stability or long-term maintenance.
All 123 recent commits came from one contributor, creating a concentrated maintenance dependency with no demonstrated backup contributor.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.