Clear documentation, tests, licensing, and a recent release provide a solid foundation. Maintenance has been quiet for three months, and all three workflow actions are unpinned, leaving meaningful upkeep and build-reproducibility concerns.
68%
Total Score
50
100
88
75
The package has existed for over nine years with 11 releases and one release in the last 12 months. The recent 4.0 release is positive, but the overall cadence is modest.
The repository recorded zero commits and zero active maintainers in the last three months. Although the latest release was pushed recently, this still indicates a thin current maintenance signal.
Composer is used for builds, but no security scanning tool was detected, leaving a modest security-process gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
The single workflow was fully analyzed with no detected dangerous sinks or audit findings, but all three action references are unpinned, weakening build reproducibility. The absence of a top-level permissions block is not a concern by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.5 || ^3.0 | — | — |
jms/serializer Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.