The package is licensed, documented, and its repository includes tests, while installation has no lifecycle scripts. Workflow credentials and unpinned actions need attention, and there is no published security policy.
61%
Total Score
50
79
75
The package is 779 days old with four releases, but only one release in the last 12 months and a median interval of about 150 days indicate a slow cadence.
One contributor made all commits in the last three months, leaving maintenance dependent on a single active person.
Only one commit was recorded in the last three months, showing limited recent maintenance activity.
Composer build tooling is present, but no security-scanning tooling was detected, leaving security hygiene less visible.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fakerphp/faker Version ^1.13 | — | — |
symfony/string Version ^5.2 | ^6.0 | ^7.0 | ^8.0 | — | — |
mmo/faker-images Version ^0.8 | ^0.9 | — | — |
illuminate/collections Version ^9 | ^10 | ^11 | ^12 | — | — |
symfony/deprecation-contracts Version ^2.1 | ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.