The README gives clear installation and usage guidance, and the package has no install-time behavior. Its small, single-owner project has limited supporting evidence for long-term maintenance.
55%
Total Score
50
100
69
83
The package has no declared license and no license file in either the artifact or linked repository, leaving its reuse terms unclear.
The registry lists one maintainer, so publishing continuity depends on a single individual. The linked repository is user-owned, making this a genuine support-capacity concern rather than normal organization publishing hygiene.
Only two releases were published, both in July 2025, with no release in the following 14 months. This is meaningful evidence of uncertain ongoing maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible adoption provides little external confidence for a young package.
Composer build tooling is present, but no security scanning tools are configured. That weakens maintenance and security-process transparency without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^6.0 | — | — |
illuminate/console Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.