Tests, release notes, and a clear MIT license support straightforward adoption. Security oversight is less visible, and the workflow dependencies are not pinned.
74%
Total Score
67
100
94
75
One contributor made all 3 commits in the last 3 months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
Only 3 commits were recorded in the last 3 months, which is modest, though the recent release history shows the project is still publishing updates.
Composer build tooling is present, but no security-scanning tool was detected, leaving security checks less visible.
The repository has no dedicated security policy. The README supplies a vulnerability contact, which partly compensates but is less transparent than a documented process.
Both workflows were analyzed without high-confidence findings or untrusted checkout and script-injection risks, but all 6 action references are unpinned and neither workflow has a top-level permissions block.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version * | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
directorytree/ldaprecord Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.