Usable with caveats: the package is licensed, linked to an active organization-owned repository, tested, and not deprecated. However, its last registry release was over three years ago, repository activity is minimal, and security-policy and workflow-permission hygiene are limited.
62%
Total Score
83
100
83
75
The package has a long history with 46 releases, but it has had no registry release in the last 12 months and the latest release was over three years ago, raising staleness concerns.
There were no new or merged pull requests and no issue activity in the measured one-month period; this indicates limited visible collaboration, although the open-issues count is unknown.
The repository reports zero stars, forks, and watchers, providing no supporting evidence of an active user or contributor community. Popularity is only supporting evidence, so this is a caution rather than a severe risk.
Composer is used as the build tool, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no SECURITY.md or other detected security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0 | — | — |
symfony/process Version ^6.0 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/support Version ^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.