Tests, release notes, and the license make ongoing use easier. The individual ownership model and completely unpinned workflow actions leave modest maintenance and build-reproducibility concerns.
82%
Total Score
63
100
94
75
Only one registry account has publish access, which creates some publishing continuity risk. The linked repository has two active maintainers, partly compensating for the narrow registry access list.
The repository is owned by an individual rather than an organization, so the small active contributor base and single registry publisher are not offset by organizational handoff capacity.
One contributor made about 77% of the 13 recent commits, but a second contributor supplied the remaining 23% and remains active. This is a modest concentration concern rather than a severe single-person failure point.
Composer build tooling is present, but no security-scanning tooling was detected. This is a minor transparency and maintenance gap, not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a modest transparency gap for a maintained package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
jaybizzle/crawler-detect Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.