This is a usable and reasonably transparent young package, with an MIT license, a stable v1.0.2 release, substantial documentation, repository tests, a complete-looking source tree, no deprecation or archival status, and no install-time scripts. The main risks are limited maturity and maintenance depth: it is only 43 days old, has just three releases, only two commits in the last three months, and all recent commits come from one contributor. The repository also lacks security scanning and a security policy, while both workflows omit top-level token permissions. These concerns warrant review before adoption in a critical system, but the current repository activity and release state do not indicate abandonment.
72%
Total Score
50
100
83
80
Only one registry account has publish access. Because the repository owner is a user rather than an organization, this aligns with a narrow publishing and maintenance base and modestly increases continuity risk.
The repository owner is a user account rather than an organization, so there is no provided organizational backing to offset the single-contributor maintenance concentration.
The package is young at 43 days with three releases and a median release interval of about 22 days. This shows ongoing early development, but provides limited evidence of long-term maturity.
One contributor made 100% of the two commits in the last three months. With user-owned backing and no second active contributor shown, maintenance continuity depends heavily on one person.
Only two commits were recorded in the last three months, indicating a low maintenance cadence. The recent push and release history are compensating evidence that the project is not currently abandoned, so this is a caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.63|^3.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.