The README is only 12 characters long, and the package requires 17 runtime dependencies. Frequent releases and an unarchived repository help, but the project has limited visible adoption and security documentation.
55%
Total Score
50
50
67
50
The package declares 17 runtime dependencies, including several extensions and substantial libraries, which increases integration and maintenance surface. No provided signal shows that this breadth is reduced or tightly managed.
A README is present, but it contains only 12 characters and offers almost no consumer guidance. Missing tests and a changelog are normal for a published artifact and are not treated as gaps here.
The repository recorded zero commits and zero active maintainers during the last three months, which is a concrete maintenance concern. The frequent registry releases provide some counterevidence, but they do not demonstrate ongoing source development.
The repository name does not match the package name and its README does not mention the package, so ownership of the published package is not clearly established by the linked source. This creates a meaningful provenance and maintenance concern.
The repository has zero stars and forks and only one watcher, indicating little visible adoption or external review. Popularity is supporting evidence rather than a verdict, so this is a moderate concern only.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.11.1 | — | — |
ledc/snowflake Version ^2.0.0 | — | — |
smalot/pdfparser Version ^2.12.3 | — | — |
vlucas/phpdotenv Version ^5.6.3 | — | — |
guzzlehttp/guzzle Version ^7.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.