Dependency-free Laravel static analysis scanner with auto-fix, baseline, and SARIF output.
60%
Total Score
caution
Usable with caveats: its only release is 150 days old and it uses a proprietary license.
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. That creates a meaningful legal and transparency concern for a package presented as open source.
This is the package's only release, published 150 days ago, so there is limited evidence of an established release track or continuing maintenance.
The repository uses Composer, but no security-scanning tooling was detected. The missing scanning layer is a modest transparency and maintenance concern.
The repository has no security policy. For a Laravel static-analysis tool that focuses on security findings, this weakens the project's documented vulnerability-reporting process.
The release is not a prerelease, but the latest version is still 0.5.4 and the package has only one recorded release. This is usable but provides limited maturity evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.