The repository has recent activity and the release includes notes, while the organization provides some continuity. One contributor carries recent work, and the registry’s reported latest version conflicts with this release.
72%
Total Score
83
100
88
75
All five recent commits came from one contributor, so maintenance depends heavily on a single person. Organization ownership provides some ability to hand off the project but does not remove the concentration risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, reducing clarity for reporting and handling vulnerabilities.
The release is a stable major-version release and recent prerelease share is zero, but the reported latest version is 1.8.3 even though the assessed release is 1.10.0, creating a metadata consistency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
blitz-php/contracts Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.