Repository tests, release notes, and a matching MIT license provide useful maintenance and transparency signals. The single maintainer, absent security policy, and limited recent commit activity leave a modest maintenance risk.
68%
Total Score
50
93
50
Only one registry account has publishing access. The repository is also owned by the same individual, so this is a genuine bus-factor concern rather than ordinary organization publishing hygiene.
The repository recorded zero commits and zero active maintainers in the last 3 months. The recent release history partly offsets this, but the current lack of observed development activity is a maintenance concern.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest hygiene gap for a package with runtime dependencies.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment.
The workflow audit completed fully and found read-only permissions with no untrusted checkout or script-injection paths. However, all three analyzed action references are unpinned and the high-confidence audit found floating latest container images, creating avoidable build reproducibility and supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1 | — | — |
ramsey/uuid Version ^4.7 | — | — |
nesbot/carbon Version ^3 | — | — |
webmozart/assert Version ^1.11|^2.1 | — | — |
illuminate/support Version ^12|^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.