Clear documentation, tests, and a changelog make integration and ongoing use easier. The project is young and lacks security scanning, while its workflow uses two unpinned actions; active recent commits and a matching repository provide useful reassurance.
80%
Total Score
100
88
50
The package is young at 147 days and has only three releases, with a median interval of about 52 days. This is limited maturity evidence, but releases continued through 5 August 2026.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully audited with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of its two action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.15 | — | — |
dompdf/dompdf Version ^2.0|^3.0 | — | — |
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/queue Version ^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.