The package has clear ownership, a matching repository, a README, and a recent release. Maintenance evidence is thin because the repository recorded no commits or active maintainers in the last three months, and it has no security policy or scanning tools.
68%
Total Score
75
100
93
75
The repository recorded zero commits and zero active maintainers in the last three months. This conflicts with the recent release and suggests limited visible development activity, so maintenance capacity is a caution.
The repository uses Composer but has no security scanning tools. That is a modest transparency and maintenance gap, not evidence that the package is unsafe by itself.
No security policy is present in the repository, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~5.0|~5.1|~5.2|~5.3|~5.4|~5.5|~5.6|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
graham-campbell/manager Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.