The repository shows recent work from three contributors and includes tests, documentation, and release notes. Its missing security policy and unpinned workflow images leave avoidable maintenance and build-integrity gaps.
67%
Total Score
83
88
50
A post-autoload-dump install lifecycle script can run package code during installation, creating some supply-chain exposure, although this signal does not show harmful behavior.
This registry release is the package's first recorded release and is only 0 days old, so there is no registry history to establish long-term stability. Recent repository activity partly offsets that uncertainty.
Three contributors were active in the last three months, but one contributor made about 71% of the 14 commits. The organization backing provides some handoff capacity, limiting this to a mild concern.
Composer build tooling is present, but no security scanning tools were detected, leaving automated vulnerability checks less visible.
The repository has no published security policy, reducing transparency about how users should report and receive fixes for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^2.9|^3.0 | — | — |
laravel/framework Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.