The project has no recorded repository commits in the last three months, and its 12 releases were concentrated into about one day. A clear README, tests, and matching MIT licensing provide useful transparency, but the single publisher and absent security policy leave limited maintenance assurance.
58%
Total Score
67
100
81
88
Only one registry account has publishing access. That is a thin publishing base, though it is partly consistent with the repository being owned by an individual rather than an organization.
The package has 12 releases, all within roughly one day, but the latest release was about six months before collection; this provides little evidence of sustained release maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful sign of currently inactive maintenance.
The repository has zero stars, forks, and watchers, offering no supporting evidence of community adoption; this is secondary to the maintenance signals and does not establish abandonment alone.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0|^6.0|^7.0|^8.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
guzzlehttp/guzzle Version ^7.0|^8.0 | — | — |
illuminate/console Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.