This release appears generally safe to depend on from a maintenance and transparency perspective: it has a clear MIT license, a matching organization-owned repository, repository tests and tooling, a security policy, regular release history, and a very recent repository push. The main concerns are that the project remains below major version 1.0, has very low public popularity, and recorded no commits or active maintainers during the last 3 months despite a recent release, which may indicate a small or intermittently active maintenance base. Workflow permission hygiene is also imperfect, although there is no evidence here of install-time lifecycle scripts, deprecation, archival, or an unmatched source repository.
78%
Total Score
88
100
89
80
One pull_request_target workflow is used for Dependabot auto-merge, but the analyzed workflows show no untrusted checkout or script-injection patterns; the workflow type warrants awareness without constituting a severe health issue.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a meaningful maintenance concern. This is partly offset by the recent package release and repository push, but the recent development activity itself is still sparse.
The repository has only 2 stars, 0 forks, and 9 watchers, indicating limited external adoption and review; this is a cautionary supporting signal rather than a decisive health failure.
Two of three workflows lack top-level permissions declarations and one workflow grants top-level write permissions, representing weaker-than-ideal CI permission hygiene. This is a repository security concern but not evidence that the package is unfit to depend on by itself.
The assessed version is a stable, non-prerelease release, but the package is still on the 0.1 major line, so its public API maturity is somewhat limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
webonyx/graphql-php Version ^15.33 | — | — |
jawira/case-converter Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.