Tests, release notes, a clear MIT license, and a security policy make the project transparent to consumers. Long-term support and workflow maintenance remain unproven, so pinning this version deserves caution.
67%
Total Score
50
88
67
The package declares post-install and post-update Composer scripts. Install-time execution adds dependency-installation complexity and warrants scrutiny, although this signal alone does not show harmful behavior.
Only two releases exist and the package is less than one day old, so there is not yet enough history to establish durable maintenance or release stability.
One contributor accounts for all recent commits, leaving no demonstrated backup maintainer. The linked repository is user-owned, so there is no organization backing shown to offset that concentration.
The repository has one commit from one active maintainer in the last three months. Because the project is newly published, this is limited evidence rather than proof of abandonment, but maintenance capacity is not yet demonstrated.
Version 0.1.1 is below a stable major release, which signals an early-stage API and a higher likelihood of compatibility changes than a mature 1.x package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.