Tests, extensive documentation, a license, and a security policy provide useful project transparency. Recent releases and active commits support continued maintenance, while all recent commits coming from one contributor and three unpinned workflow actions add caution.
72%
Total Score
83
100
94
88
All 12 recent commits came from one contributor, creating a meaningful continuity risk; organization ownership provides some capacity to hand maintenance off, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tool was detected, leaving automated security coverage less clear.
The workflow is fully analyzed, uses read-only permissions, and has no reported audit findings or untrusted execution sinks. However, all three action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.