The package is well documented, licensed, and published regularly. It lacks a security policy and automated security scanning, leaving maintenance and security transparency dependent on a very small contributor base.
72%
Total Score
50
100
86
75
One contributor made all 58 commits in the last three months, giving the project a bus factor of one. The active commit volume helps, but does not offset the concentration risk.
The repository recorded 58 commits in the last three months, showing active development. However, all activity came from one active maintainer, which limits resilience.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning reduces security-process transparency, although it is not evidence of malicious behavior.
The linked repository has no security policy. For a CMS core package handling permissions, files, and database migrations, this is a genuine transparency and vulnerability-reporting gap.
Version 0.12.1 is not a stable major release, but it is not prerelease and recent releases contain no prerelease versions. This is a mild maturity limitation rather than a serious health concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.0||^8.0 | — | — |
laravel/scout Version ^10.20||^11.1 | — | — |
laravel/framework Version ^11.0||^12.0||^13.0 | — | — |
intervention/image Version ^3.11 | — | — |
ezyang/htmlpurifier Version ^4.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.