Tests, a README, a clear MIT license, and a small runtime dependency set improve transparency and integration confidence. The missing security policy and scanning reduce assurance for a package with little recent project activity.
39%
Total Score
25
100
75
88
The latest release was over 7 years ago, with no releases in the last 12 months. Four releases show an established history, but the prolonged release gap is a serious maintenance concern.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has not had meaningful source maintenance for years.
The registry namespace and repository owner match, but the backing is an individual user account rather than an organization; this provides limited evidence of ongoing support.
The repository name does not match the package name and its README does not mention the package, creating uncertainty that the linked repository is the package's actual source.
Composer build tooling is present, but no security scanning tools were detected. That is a maintenance and assurance gap, though not severe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.6 | — | — |
vinkla/hashids Version ^5.0 | — | — |
laravel/passport Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.