Its README and matching source repository make the small extension straightforward to inspect. The project has no security scanning and limited testing evidence, which leaves future compatibility and vulnerability response less visible.
58%
Total Score
50
100
71
75
Only two releases exist, and none were published in the last 12 months; the latest release was about 19 months ago. This indicates a dormant project, though a small extension may not require frequent releases.
The repository had zero commits and zero active maintainers in the last three months. Combined with the older latest release, this is evidence of currently inactive maintenance.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP extension this is a modest transparency and vulnerability-response gap.
The linked repository is not archived, but its last push was about 19 months ago. The unarchived status preserves the possibility of maintenance without offsetting the observed inactivity.
The repository has no security policy, so users have no documented reporting path or stated vulnerability-handling process. This is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dedoc/scramble Version ^0.11.9||^0.12.10 | — | — |
spatie/laravel-model-states Version ^2.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.