Usable with caveats: the release is well documented, tested, licensed, and not deprecated, but it is a young 0.x package with only one recent commit from one maintainer. The repository also lacks a security policy and explicit workflow token permissions.
63%
Total Score
50
100
75
67
The package is only 100 days old and has made 10 releases in about one week, with releases arriving roughly every 10 hours; this shows active iteration but limited long-term stability evidence.
All recent commits come from one contributor, creating a concentrated maintenance dependency; the repository owner is an individual rather than an organization.
Only 1 commit was recorded in the last 3 months, which is thin evidence of ongoing maintenance for a package released only 100 days ago.
The repository has 0 stars, forks, and watchers. This is not decisive for a young package, but it provides no supporting evidence of broader review or adoption.
Composer build tooling is present, but no security scanning tools were detected, leaving security-oriented maintenance coverage less visible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7|^8 | — | — |
illuminate/support Version ^11|^12|^13 | — | — |
woduda/civicrm-php Version ^1.0 | — | — |
illuminate/contracts Version ^11|^12|^13 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.