Apache-2.0 licensing, a focused README, and organization backing improve transparency. The package has no install scripts and its repository matches the package, but its maintenance record is not yet established.
68%
Total Score
75
100
88
88
The package is brand new: it has one release, published today, with no established release cadence. This limits evidence of sustained maintenance but is not abandonment evidence by itself.
There were no commits or active maintainers in the last three months, but the repository was created or updated today; this confirms that a longer maintenance record is unavailable rather than showing a collapse in activity.
Composer is used as the build tool, fitting the package, but no security scanning tooling was detected. For this tiny metapackage that is a modest hygiene gap rather than a severe risk.
The repository has no security policy. This reduces reporting transparency, although the package is a small dependency-only metapackage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/larastan-larastan-impl Version ~3.12.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.