The organization-owned repository matches the package, and its README clearly explains the metapackage relationship. Apache-2.0 licensing and a clean install profile help, but there is not yet enough history to establish durable maintenance.
72%
Total Score
100
100
88
88
The package is newly published, with only 2 releases and both released within about 16 minutes. This limits evidence of sustained maintenance, although the repository and project backing provide some transparency.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools were detected, leaving a minor repository-hygiene gap for a newly published package.
The repository has no security policy. For a small metapackage with no install scripts and minimal files this is a limited transparency gap, but it provides no documented vulnerability-reporting path.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/illuminate-reflection-impl Version ~13.33.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.