It has a clear MIT license, tests, changelog, release notes, and an active organization-backed repository. The small recent contributor base and absent security policy leave meaningful maintenance and security-process concerns.
68%
Total Score
75
50
88
75
The package declares 11 runtime dependencies, including framework and integration components; this is a substantial dependency surface but not severe on its own.
The package has 210 releases over more than 10 years, but none in the last 12 months; this suggests release maintenance has slowed despite the long history.
All recent commit activity comes from one contributor, creating a high concentration risk; organization backing provides some ability to hand off maintenance but does not remove the concern.
Only one commit was recorded in the last three months, indicating limited recent development activity even though the repository was pushed recently.
Composer is used for builds, but no security scanning tools were detected, leaving the project with limited automated security coverage.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version >=2.3 | — | — |
erusev/parsedown Version 1.* | — | — |
laravel/framework Version >=5.5 | — | — |
kodicms/laravel-assets Version 0.* | — | — |
kodicomponents/support Version 0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.