The package includes tests, a useful README, and release notes for this version. Organization backing and recent commits help, but workflow pinning and the single-contributor history merit monitoring.
67%
Total Score
83
88
75
This is a young package, 96 days old, with only one release and no established release cadence. That limits evidence of long-term maintenance but does not by itself indicate abandonment.
One contributor made all 6 commits in the last 3 months, creating a thin maintenance base and elevated continuity risk. Organization backing partly compensates because maintenance can potentially be handed off.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap for a dependency published to a registry.
The repository has no security policy. This is a maintenance and disclosure-process gap, though it is not evidence that the release is unsafe.
Both workflows were analyzed with no audit findings or untrusted-trigger sinks, but all 5 action references are unpinned and one workflow grants top-level write permissions. These are workflow hygiene concerns rather than severe risks here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
opensearch-project/opensearch-php Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.