The package is licensed, documented, and backed by a matching source repository with a clear file tree. Its stable history and recent publication support continued use, but security-process coverage is limited.
70%
Total Score
75
94
67
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The current release and same-day push provide some compensation, but recent development activity is still thin.
Composer build tooling is present, but no security-scanning tooling was detected. This is a process gap rather than evidence of an unsafe release.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 3 analyzed action references are unpinned, which weakens workflow reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
konekt/enum Version ^4.1 | — | — |
konekt/xtend Version ^1.2|^2.0 | — | — |
doctrine/dbal Version ^3.5.1|^4.0 | — | — |
konekt/concord Version ^1.14 | — | — |
illuminate/support Version ^12.61.1|^13.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.