The package has clear documentation, tests, a recent release, and no install-time scripts. Its maintenance depends on one contributor, while the workflow uses two unpinned actions and the repository has no security policy.
72%
Total Score
83
92
67
The package has existed since December 2020 and released version 13.1 in August 2026, but only one release arrived in the last 12 months and the median interval is about 322 days. This indicates slow, rather than abandoned, release activity.
One contributor made all four commits in the last three months, leaving maintenance concentrated in a single person and increasing continuity risk.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a library that processes external exchange-rate services.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both action references are unpinned. The absence of a top-level permissions block is not a concern on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^13 | — | — |
florianv/exchanger Version ^2.9 | — | — |
illuminate/support Version ^13 | — | — |
guzzlehttp/promises Version ^2.0 | — | — |
php-http/guzzle7-adapter Version ^0.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.