Clear documentation, tests, licensing, and a busy recent release history provide useful support. The missing security policy is a smaller transparency gap.
76%
Total Score
67
100
75
The repository is owned by a user account rather than an organization, so there is no observed organizational backing to offset the single-contributor concentration.
All 148 recent commits came from one contributor, so maintenance depends heavily on a single person and has limited handoff resilience.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, but it is less severe than an inactive or archived project.
The workflow audit completed cleanly, uses read-only permissions, and found no high-confidence dangerous patterns. However, all five analyzed action references are unpinned, reducing build reproducibility and supply-chain resilience.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version ^0.12 || ^0.13 || ^0.14 | — | — |
symfony/yaml Version ^7.0 | — | — |
fakerphp/faker Version ^1.23 | — | — |
brick/varexporter Version ^0.7.0 | — | — |
laravel/framework Version ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.