Clear documentation, tests, licensing, and release notes make integration straightforward. The small maintainer base and limited recent repository activity leave more continuity risk than the release history alone suggests.
68%
Total Score
50
100
94
88
Only one account has registry publish access. Because the repository is user-owned rather than organization-owned, there is no provided organizational backing to offset this concentration.
The registry namespace and repository are owned by the same individual account, and the repository owner is a user rather than an organization. This supports identity continuity but provides no visible institutional backing.
One contributor made all commits in the last 3 months, with a 100% share. The user-owned project provides no shown organizational handoff capacity to compensate for this concentration.
Only 1 commit was recorded in the last 3 months, indicating limited recent development activity despite the recent release.
The repository has 66 open issues, but recorded activity in the last month is zero for both new and closed issues and pull requests. This weakens evidence of responsive maintenance.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-29931 hhxsv5/laravel-s is vulnerable to Files or Directories Accessible to External Parties in versions 0.0.0 - 3.7.36. | 0.0.0 - 3.7.36 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version >=6.4.0 | — | — |
swoole/ide-helper Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.