The MIT license, matching repository, clear README, and absence of install scripts are reassuring. A single maintainer and no security policy leave less support and disclosure evidence.
62%
Total Score
67
100
83
88
Only one registry account has publish access, which creates a thin publishing base. The repository is user-owned rather than organization-backed, so there is no provided evidence of broader maintenance capacity.
This package is only 116 days old and has one release, so its maintenance record is not yet established. That is a meaningful maturity gap, but not evidence of abandonment by itself.
There were zero commits and zero active maintainers in the last three months. For a package this new, that leaves limited evidence of ongoing maintenance and raises support risk.
The repository has no stars, forks, or watchers. Popularity is only supporting evidence, so this modestly limits external validation but does not determine health.
The repository uses Composer tooling, but no security-scanning tool was detected. This is a modest transparency and maintenance-hygiene gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.