Clear documentation, tests, release notes, and recent two-person activity support dependable maintenance. Pin the floating container image before relying on its CI supply chain; no security policy or scanning is also a modest transparency gap.
82%
Total Score
80
100
94
75
One registry maintainer is consistent with a user-owned project, and the repository activity shows two active contributors; this is adequate but not broad redundancy.
The package and repository are consistently owned by the same individual user, supporting identity alignment, though there is no organization backing to broaden handoff capacity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest gap in automated security hygiene.
The repository has no security policy, which makes vulnerability reporting and disclosure expectations less transparent.
The sole workflow was fully analyzed with no untrusted checkout or script-injection findings, but it uses four unpinned references and a high-confidence unpinned container image tagged latest.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.