Healthy and suitable to use, with a narrow maintenance caveat. It has regular releases, a current stable version, active organizational backing, tests, release notes, and a matching repository, but recent repository activity is limited to one contributor and the workflow lacks explicit token permissions.
78%
Total Score
70
100
94
67
All one commit in the last three months came from a single contributor. Organizational ownership provides some handoff capacity, but the observed recent activity remains concentrated.
Only one commit was recorded in the last three months, indicating a sharp short-term slowdown despite the recent release history.
There was one merged pull request in the last month, but no new or closed issues and no new pull requests, showing limited recent community activity.
The repository uses Composer and Box for builds, which supports repeatable packaging, but no automated security-scanning tool was detected.
The README gives a security contact, but the repository has no formal security policy file. This is a transparency gap for vulnerability handling, not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-zero/phar-updater Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.