Usable with caveats: the release is licensed, well documented, tested, and backed by a matching repository with active issue and pull-request handling. However, the repository had no commits from any maintainer in the last three months, and its workflow security posture is incomplete.
68%
Total Score
50
100
89
83
No commits were recorded from any active maintainer during the last three months. This is the clearest maintenance concern, especially for a security-sensitive sharing-link package.
Only one registry account has publish access, which creates some publishing continuity risk. The repository is user-owned rather than organization-owned, so there is no organizational backing shown to compensate for that narrow base.
The registry namespace and repository owner both identify Grazulex, but the owner is an individual account rather than an organization. This supports repository continuity but does not provide a broader maintainer base.
The package is 404 days old with four releases and two releases in the last 12 months, indicating an established but relatively infrequent release cadence.
Composer build tooling is present, but no repository security-scanning tool was detected. The missing scanning is a transparency gap, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 | — | — |
nesbot/carbon Version ^3.10 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.