Healthy and suitable to depend on. It has a long, active release history, current repository activity, clear documentation and tests in the source repository; the main caveats are limited security-policy coverage and permissive workflow settings.
88%
Total Score
88
100
94
70
One of two workflows uses pull_request_target, which warrants review because that trigger can run with elevated repository context, although no untrusted checkout or script-injection pattern was detected.
Only one registry publishing account is listed, which creates some publishing continuity risk, although the repository shows activity from two contributors.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency gap.
The repository has no security policy, so vulnerability-reporting and response expectations are not documented.
One workflow lacks top-level token permissions and another grants top-level write permissions, leaving the CI authorization model broader or less explicit than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
mateusjunges/avro-serde-php Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.