This is a healthy, actively published release with a stable major version, 38 releases over roughly 625 days, a recent release and repository push, an organization-backed repository, matching package references, tests, a clear README, and a licensed MIT codebase. Maintenance activity is modest at two commits in the last three months, and the repository lacks a security policy, automated security scanning, and top-level workflow permissions, but the analyzed workflows show no dangerous trigger, checkout, or script-injection patterns; these are transparency and hardening gaps rather than evidence of abandonment. The package appears reasonable to depend on, with normal operational monitoring appropriate for a CLI tool.
84%
Total Score
80
100
89
80
Only two commits were recorded in the last three months, indicating modest recent development activity. The recent release and repository push, plus two active maintainers, partially offset but do not eliminate this maintenance concern.
There are no open issues or pull requests and no recent issue or pull-request activity. This is ambiguous for a small project: it provides little evidence of community engagement but does not demonstrate unresolved maintenance problems.
The repository has zero stars and forks and only two watchers. This limits popularity-based supporting evidence, but popularity is not required for a small, maintained package and does not independently indicate poor health.
Composer and Box provide explicit build tooling, supporting reproducible packaging, but no security-scanning tools are configured. The missing scanning is a hardening gap rather than a direct health failure.
No repository security policy was found, reducing vulnerability-reporting transparency. This is a documentation gap, not evidence that the package is abandoned or unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 | — | — |
laravel/forge-sdk Version ^4 | — | — |
intonate/tinker-zero Version ^1.2 | — | — |
illuminate/validation Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.