The package is clearly documented and licensed, with repository tests and release notes for this version. Install-time scripting and fully unpinned workflow actions add avoidable review burden.
76%
Total Score
75
100
93
67
The post-autoload-dump lifecycle script runs package code during Composer installation, creating an additional supply-chain review point even though no other evidence shows abuse.
All 26 commits in the last 3 months came from one contributor, so maintenance is vulnerable to that person's absence despite the repository being organization-owned.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and assurance gap.
Both workflows were fully audited with no untrusted checkouts, script injection, or audit findings, but all 20 action references are unpinned. The absence of a top-level permissions block is acceptable here because no workflow requests top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
laravel/framework Version ^9.0.0|^10.0.0|^11.0.0|^12.0.0|^13.0.0 | — | — |
jaybizzle/crawler-detect Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.