Healthy and suitable to depend on, with modest caveats. It has an active organizational owner, a recent stable release, tests, documentation, and a clear license, but no commits or active maintainers were observed in the last three months and its workflow lacks explicit top-level permissions.
78%
Total Score
67
100
94
80
The package defines pre-install and post-install Composer scripts. Install-time scripts deserve review because they execute during installation, although this signal alone does not establish that they are unsafe.
No commits and no active maintainers were observed during the last three months. The recent release is compensating evidence of publishing activity, but the lack of recent development activity raises a maintenance concern.
There is one open issue and one open pull request, but neither new issues nor pull requests were recorded as opened or merged in the last month. This suggests limited current community activity without proving abandonment.
The repository uses Composer, but no security scanning tools were detected. The absence of scanning reduces process transparency, while the simple build setup limits the significance of this gap.
The only workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege settings would provide stronger workflow transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/once Version ^3.1 | — | — |
alleyinteractive/laminas-validator-extensions Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.