The organization-owned project and frequent releases provide useful continuity. Documentation, tests, and a changelog make integration easier. No security policy or automated security scanning is visible, so ongoing oversight is limited.
70%
Total Score
75
50
94
50
Sixteen runtime dependencies, including several provider SDKs and Laravel components, create a relatively broad dependency surface for this messaging package and increase maintenance exposure.
All recent commits came from one contributor, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity but does not remove the current concentration.
Only 1 commit was recorded in the last 3 months, with 1 active maintainer. This is evidence of limited recent development activity despite the stronger release cadence.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest gap in repository oversight.
The repository has no published security policy, reducing transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twilio/sdk Version ^6.0 | — | — |
vonage/client Version ^4.2 | — | — |
illuminate/http Version ^10 || ^11 || ^12 || ^13 | — | — |
illuminate/mail Version ^10 || ^11 || ^12 || ^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.