The package is well documented, tested, licensed, and has a focused dependency set with no install-time scripts. A single maintainer, no security policy, and limited repository adoption reduce confidence for long-term use.
62%
Total Score
67
100
83
75
Only one registry account has publishing access. That is not itself evidence of poor health for a user-owned project, but it leaves little visible publishing redundancy.
The package has 15 releases since September 2020, but none in the last 12 months and the latest release was in November 2024. Its established history helps, but the prolonged release gap raises maintenance concerns.
There were zero commits and zero active maintainers in the last three months. This reinforces the release gap and lowers confidence that maintenance is currently active.
The repository has one star, one fork, and one watcher. Low adoption is supporting evidence rather than a verdict, but it provides little external confidence or resilience.
The repository uses Make and Composer, showing basic build tooling, but no security scanning tools are configured. The missing scanning is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
illuminate/support Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.