Clear documentation, a matching repository, and an MIT license make adoption straightforward. Automated security tooling and two active contributors provide useful maintenance coverage, though install-time scripting and unpinned workflow actions warrant routine review.
84%
Total Score
83
94
75
The package declares a post-autoload-dump install-time script, which adds execution during Composer operations. No provided signal shows that this script is harmful, so this is a limited supply-chain hygiene concern.
The registry namespace and repository are owned by the same individual, so the package has clear ownership but no organizational backing indicated. The second active contributor partly offsets that limitation.
Version v0.2.1 is not a stable major release, so its API may still change. It is not marked as a prerelease, reducing the concern somewhat.
All three workflows were analyzed with no audit findings or untrusted checkouts. However, all eight action references are unpinned and one workflow grants top-level write access; these are hygiene concerns without a demonstrated dangerous sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version ^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19 || ^0.20 || ^1.0 | — | — |
illuminate/http Version ^12.0||^13.0 | — | — |
illuminate/cache Version ^12.0||^13.0 | — | — |
illuminate/console Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.