Documentation, licensing, and recent repository activity support adoption. The small active contributor base and unpinned workflow actions increase maintenance and build-reproducibility risk, while the missing security policy is a smaller transparency gap.
68%
Total Score
63
94
50
post-install-cmd and post-update-cmd scripts run during Composer operations, adding execution surface that consumers should inspect before adoption.
All recent commits came from one contributor, but the repository is organization-owned, which provides some capacity for maintenance handoff.
Only one commit was recorded in the last three months, indicating sparse recent development even though the repository was recently pushed.
Five open pull requests and one open issue remain, while no issues or pull requests were merged in the last month; this suggests limited recent review throughput.
The repository has no security policy, leaving vulnerability-reporting expectations less transparent for a package that integrates into applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.4|^8.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
sentry/sentry-laravel Version ^4.20 | — | — |
mochaka/serialization-parser Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.