The repository includes tests, release notes, and a clear package match. Workflow actions are unpinned and no security policy is provided, adding maintenance and build-integrity concerns.
60%
Total Score
50
50
81
75
Seven runtime dependencies, including several framework components and dotenv, create a meaningful compatibility surface for a small integration package, though no specific dependency failure is shown.
The package and repository are owned by the same individual account, providing direct ownership alignment but not the resilience of an organization-backed maintainer base.
Seven releases arrived within about two days, showing an active initial push but little evidence of a sustained release pattern over the package's roughly five-month history.
There were no commits and no active maintainers in the last three months, a significant warning for a package only about five months old.
Composer build tooling is present, but no security scanning tools are configured, leaving supply-chain checks less visible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
marko/view Version ^0.4 | — | — |
illuminate/view Version ^11.0 || ^12.0 || ^13.0 | — | — |
vlucas/phpdotenv Version ^5.4.1 | — | — |
illuminate/events Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/container Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.