The package is very new, so its long-term maintenance record is not established. Documentation, repository tests, organization backing, and read-only workflow permissions are positive, but the workflows use unpinned actions and the repository has no security policy or scanning tool.
62%
Total Score
75
100
86
67
This package is less than one day old with only two releases, so there is not yet enough history to demonstrate sustained maintenance or release stability.
No commits or active maintainers were recorded in the last three months, but the package itself is less than one day old and the repository was pushed recently, making this primarily an unproven maintenance record rather than strong abandonment evidence.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap in the project tooling.
The repository has no security policy, reducing transparency about how users should report and receive fixes for vulnerabilities.
The workflow audit completed cleanly and found read-only permissions with no untrusted checkouts or injection findings, but both analyzed action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
illuminate/log Version ^12.0 || ^13.0 | — | — |
illuminate/http Version ^12.0 || ^13.0 | — | — |
livck/cloud-php Version ^1.0 | — | — |
psr/http-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.