The repository has tests, a README, a license, and a release note for this version. Its small maintenance footprint, absent security policy, and fully unpinned workflow actions increase the cost of relying on it.
58%
Total Score
50
81
75
The latest release was about 15 months ago, with no releases in the last 12 months. The six-release history shows an initially active cadence but does not offset the current inactivity.
There were no commits and no active maintainers in the last 3 months. This is meaningful maintenance evidence and aligns with the long gap since the latest registry release.
The repository uses Composer, but no security scanning tools were detected. That is a transparency and maintenance gap, though it is not severe on its own.
No security policy was found in the repository, leaving vulnerability reporting and response expectations unclear.
Version 0.3.2 is not a stable major release, so compatibility expectations are weaker for consumers. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/routing Version ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
illuminate/support Version ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
promphp/prometheus_client_php Version ^2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.