The package includes a clear MIT license, substantial documentation, tests, and a changelog, with no install-time scripts. Its single-maintainer project has no security policy or scanning tools, so future fixes and review capacity are limited.
58%
Total Score
50
88
75
The package is about 1 year old but has had no releases in the last 12 months; all three releases were published within roughly two minutes, indicating a stalled and very short release history.
The repository had 0 commits and 0 active maintainers in the last 3 months, which provides no evidence of ongoing maintenance despite the repository not being archived.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in a package that handles cryptocurrency RPC integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/console Version ^11.0|^12.0 | — | — |
illuminate/support Version ^11.0|^12.0 | — | — |
illuminate/contracts Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.