Organization backing, a matching repository, clear licensing, and release notes support confidence. Workflow references are all unpinned, and the repository has no security policy or scanning, leaving avoidable maintenance and build-hygiene gaps.
62%
Total Score
75
100
88
75
The package has 83 releases over about 4.5 years, but only one release in the last 12 months despite a historical median interval of about 6 days, indicating a marked slowdown.
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of currently weak maintenance activity.
Composer build tooling is present, but no security-scanning tools were detected, leaving security hygiene less visible.
The repository has no security policy, so users lack a documented process for reporting vulnerabilities or understanding security response expectations.
All 5 workflow action references are unpinned, and the sole workflow grants top-level write permissions. The audit found no untrusted checkout, script injection, or other detected high-confidence issue, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nelexa/zip Version ^4.0 | — | — |
laravel/framework Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
wikimedia/composer-merge-plugin Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.