There is no security policy or automated security scanning, which leaves maintenance and disclosure practices unclear. The MIT license, documented release notes, repository tests, and clean workflow audit provide useful transparency and build hygiene.
68%
Total Score
50
86
75
The package is only 0 days old, with all 7 releases published within roughly 15 hours; this shows active initial work but gives no evidence of sustained maintenance.
No commits or active maintainers were recorded in the previous 3 months, but the repository itself is newly established and was pushed on the assessment date; this limits the strength of the negative result.
Composer build tooling is present, but no security-scanning tools were detected, leaving automated vulnerability checks absent.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 3.28.* | — | — |
filp/whoops Version 2.18.* | — | — |
geoip2/geoip2 Version ^3 | — | — |
aws/aws-sdk-php Version 3.394.* | — | — |
firebase/php-jwt Version 7.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.