The MIT license, usable README, tests, and regular releases provide good transparency and integration support. There is no registry deprecation or install-time script to add operational concern.
66%
Total Score
50
94
75
Only one registry account has publish access. The repository is user-owned, so the narrow publishing base provides limited redundancy even though recent releases show activity.
One contributor made all commits during the last three months, giving the project a complete recent commit concentration. With user ownership rather than organization backing, handoff capacity is limited.
The repository recorded only one commit in the last three months. Recent registry releases partly offset this, but the source maintenance pace is thin.
Composer build tooling is present, but no security scanning tools were detected. This is a moderate transparency and maintenance gap rather than a standalone severe risk.
The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented, which modestly lowers project transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version >=6.4 | — | — |
symfony/routing Version >=6.4 | — | — |
hurah/data-types Version >=v1.1 | — | — |
vlucas/phpdotenv Version 5.6.x-dev | — | — |
guzzlehttp/guzzle Version >=7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.