The package is small and clearly documented, with a focused dependency set and organization backing. Its release and maintenance record is too new to establish reliability, and it lacks tests, security scanning, and a security policy.
60%
Total Score
67
81
75
This release is from a package that is 0 days old with only one release, so there is no track record for maintenance or release reliability.
One contributor made 100% of the single recent commit, leaving maintenance dependent on one active person. Organization ownership provides some backing but does not show a second active contributor.
The repository has only 1 commit in the last 3 months, which is consistent with a newly created project but does not yet demonstrate sustained maintenance.
Composer build tooling is present, but no security scanning tooling was observed, reducing automated coverage for supply-chain and dependency issues.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.68|^13.27 | — | — |
shopper/shipping Version self.version | — | — |
illuminate/support Version ^12.68|^13.27 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.