The package includes tests, a README, and an MIT license. Its small dependency surface and matching repository make the contents easy to inspect, but install-time code and weak workflow pinning add maintenance friction.
52%
Total Score
50
100
70
50
There has been only one release, published about three years ago, with no releases in the last 12 months. This is strong evidence of limited ongoing maintenance.
A post-autoload-dump install-time script runs during Composer operations. This is not inherently unsafe, but it adds execution during installation and deserves review in an otherwise inactive package.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the absence of recent release activity.
The repository has no published security policy. For a small package this is a transparency gap, though it is less significant than the lack of maintenance activity.
Version v0.0.1 is an early, non-stable-major release, so compatibility and maturity are less established than for a stable major version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.