The package includes a clear README, changelog, repository tests, and a matching source project. Its small dependency set and MIT license help, but pin this exact version until a longer maintenance record emerges.
57%
Total Score
50
100
79
50
The package is only 0 days old with two releases, both published within minutes, so there is not yet evidence of an established release process. Its changelog and repository documentation provide some transparency.
There were zero commits and zero active maintainers in the preceding three months. Because the package was created only moments earlier, this is mainly missing maintenance history rather than evidence of a collapsed established project.
Composer build tooling is present, but no security scanning tools were detected. For a brand-new package this leaves a modest transparency and verification gap.
The repository has no security policy. That does not prove unsafe code, but it weakens the project's stated process for handling vulnerabilities.
Version v0.1.1 is pre-1.0, which indicates an immature compatibility commitment. The release is not marked as a prerelease, partially offsetting that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.