Usable with caveats: the package is actively published, documented, tested in its repository, and backed by an organization. It is only 55 days old, has one active contributor, and runs a Composer install-time script, so maintenance continuity and installation behavior deserve review.
72%
Total Score
83
86
88
The package runs a post-autoload-dump Composer install-time script. This is not inherently unsafe, but it adds installation behavior that dependents should inspect before adopting the release.
The package is only 55 days old and has shipped 8 releases, with a median interval of about 53 minutes. This shows active early development but not yet a long record of stable maintenance.
One contributor made all 20 commits in the last 3 months, giving the project a very concentrated maintenance base. Organization backing provides some handoff capacity, but no second active contributor is evidenced.
Version v0.3.5 is not a stable major release, although it is not marked as a prerelease and recent releases contain no prerelease versions. The 0.x version still indicates an evolving API.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.