Clear licensing, substantial documentation, tests, and release notes make the package easy to evaluate. Its small runtime dependency set and matching repository are reassuring, but ongoing ownership evidence is limited.
66%
Total Score
50
100
94
67
A post-autoload-dump script runs during Composer installation. This adds some execution surface, but the signal does not show suspicious behavior or an unusually broad script set.
The repository owner is an individual rather than an organization, so the single registry maintainer represents a relatively thin ownership base. Recent releases and repository activity provide partial compensation.
The repository recorded zero commits and zero active maintainers in the last three months. The April 22, 2026 release partly offsets this, but the current activity gap still raises maintenance concern.
Composer and Box provide build tooling, but no security-scanning tool was detected. The missing scanning coverage is a modest transparency and maintenance gap, not evidence of a defect.
The repository has no security policy. This weakens disclosure transparency for a library, although the strong documentation and release process provide some compensating project evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.