Healthy and suitable to depend on, with a small maintainer-base caveat. It has active recent development, clear release documentation, tests, and a matching source repository, but most recent commits come from one contributor and the repository has no security policy or scanning tools.
82%
Total Score
67
89
90
The registry namespace and repository owner match, but the owner is an individual rather than an organization; this is consistent with the concentrated contributor profile and provides limited institutional continuity.
Two contributors are active, but one accounts for about 90% of recent commits, leaving meaningful dependence on a single individual.
The repository has only 9 stars and no forks, which limits supporting evidence of broad adoption; active maintenance and project quality compensate for this as a maturity concern.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
The repository has no SECURITY.md or other detected security policy, so the process for reporting and handling vulnerabilities is unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.