The package is actively released and the repository is current, with a stable version and matching source tree. Its single-contributor base, absent readme, and lack of security policy leave less protection for long-term use.
68%
Total Score
50
88
67
The package defines a post-update-cmd lifecycle script, adding install or update behavior beyond ordinary file installation. This is a modest transparency and supply-chain concern, not a severe risk by itself.
Only one registry account has publish access. Because registry access lists are administrative rather than activity evidence, this is a limited concern and is reinforced mainly by the repository's contributor concentration.
The package has no readme, which matters for a reusable PHP library that consumers must integrate against. Missing tests and a changelog are normal packaging practice here and are not counted as gaps.
The repository is owned by an individual rather than an organization, and the activity data shows one active contributor. This provides no visible institutional maintenance cushion.
All 37 commits in the last three months came from one contributor, giving the project a complete single-person bus factor. No organizational backing is shown to provide an obvious handoff path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.4 | — | — |
symfony/process Version ^8.0 | — | — |
illuminate/support Version ^13.0 | — | — |
symfony/filesystem Version ^8.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.