This release appears generally suitable to depend on: it is a licensed, non-deprecated stable release from a repository that is actively published, has substantial source and artifact documentation, repository tests, changelog and release support, and clear organization backing. The main concerns are that only two commits were recorded in the last three months, all by one contributor, the project has no security scanning or security policy, and several workflows use broad or unspecified token permissions, including a workflow with pull-request-target and untrusted checkout behavior. The package also has a large runtime dependency surface, increasing maintenance complexity, but its long release history and recent release activity materially offset that concern.
78%
Total Score
80
50
94
70
One workflow uses pull-request-target with an untrusted checkout, creating a meaningful CI supply-chain exposure even though no script injection was detected in the analyzed workflows.
The package declares 61 runtime dependencies, including framework, database, payment, authentication, and asset-processing components; this is a substantial dependency surface that increases update and compatibility complexity.
All two recent commits came from one contributor, producing a 100% top-contributor share. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown in this period.
Only two commits were recorded in the last three months, with one active maintainer. This is materially slower than the release history suggests and warrants caution about current maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected. The build setup is established, while security-process coverage is incomplete.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
cycle/orm Version ^2.8.0 | — | — |
ramsey/uuid Version ^4.7 | — | — |
tracy/tracy Version ^2.10 | — | — |
league/glide Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.