Composer metadata is clean, licensing is explicit, and the repository contains tests. Organizational ownership and a matching repository provide useful context, but there is not yet enough history to establish durability.
65%
Total Score
75
100
86
75
The package was first released today and has only one release, so there is no track record for maintenance or release reliability yet.
There were zero commits and zero active maintainers in the measured three-month window. Because the repository is newly created, this is mainly unproven maintenance capacity rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and hygiene gap, not a severe dependency risk on its own.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself show that the package is unsafe to use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/validation Version 13.32.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.