Tests, a useful README, and a matching source repository provide a solid starting point. The workflow uses read-only permissions, but its three actions are unpinned and the repository has no security policy.
65%
Total Score
50
81
75
The package was first released today and has only three releases, all within roughly three hours, so there is not yet evidence of sustained maintenance.
There were no commits or active maintainers during the preceding three months; because the project is less than a day old, this is weak evidence but still leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tools were detected, leaving security-review automation unconfirmed.
The repository has no security policy, making vulnerability reporting and response expectations less transparent for a package handling captcha verification.
Version v0.1.2 is an early 0.1.x release rather than a stable major release, which indicates an immature API and limited production history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
altcha-org/altcha Version ^2.3 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.