It includes a substantial README, repository tests, a changelog, and exact-version release notes. The small project has no security policy, and its workflow uses three unpinned actions.
68%
Total Score
50
100
94
67
The repository recorded no commits and no active maintainers in the last 3 months. This is a meaningful maintenance concern, although the assessed release was published recently.
There is limited recent issue activity, with one new issue and no closures in the last month. The small volume is not severe, but it provides little evidence of ongoing responsiveness.
The project uses Composer build tooling, but no security scanning tools were detected, leaving automated security hygiene weaker than it could be.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or write permissions. However, all 3 action references are unpinned, which is a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ~4.0|~5.0 | — | — |
symfony/mercure Version ~0.4 | — | — |
illuminate/broadcasting Version ~6.0|~7.0|~8.0|~9.0|~10.0|~11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.