Healthy and suitable to depend on. It has frequent releases, recent activity from three contributors, tests, clear licensing, and an unarchived organization-backed repository; the main caveats are limited security tooling and no documented security policy.
88%
Total Score
100
100
94
80
Composer and Make tooling are present, but no security scanning tools were detected, leaving a modest security-maintenance gap.
The repository has no security policy, leaving reporting and response expectations undocumented; this is a transparency gap but not evidence of abandonment.
Three of four workflows lack top-level token permissions, although none declares top-level write access and some permissions are read-only or job-scoped; this warrants a small hygiene caveat.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3 || ^4 | — | — |
nesbot/carbon Version ^2.62.1 || ^3 | — | — |
illuminate/support Version ^8.73 || ^9 || ^10 || ^11 || ^12 | — | — |
mll-lab/str_putcsv Version ^1 | — | — |
thecodingmachine/safe Version ^1 || ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.