The README is detailed and the package is clearly licensed, with the repository matching the package. Its zero commits in three months and pre-1.0 version make long-term maintenance less certain.
65%
Total Score
67
89
75
The repository recorded zero commits and zero active maintainers in the last three months. Frequent registry releases provide some counterevidence, but this still weakens confidence in active source maintenance.
There are only two open issues and no new or closed issues or pull requests in the last month. This is limited evidence of current community activity, though it does not by itself show abandonment.
Composer build tooling is present, but no security-scanning tools are detected. That is a maintenance and review gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version v0.0.53 is not a stable major release, so compatibility may change and the package remains less mature than a 1.0+ dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mustache/mustache Version ^2.12 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
intervention/image Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.