Documentation, tests, and a recorded release make the package easier to evaluate. The sole maintainer, absent security scanning, and no commits in three months leave maintenance capacity uncertain.
60%
Total Score
50
100
94
75
One registry maintainer concentrates publishing responsibility in a single person; the linked repository is user-owned, so there is no organization backing shown to offset that concentration.
The repository shows 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern for this young package.
Composer and Box provide build tooling, but no security scanning tools are configured, leaving a preventive hygiene gap.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities, though this is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.17 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
laravel-zero/phar-updater Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.