The package has a clear README, release notes, and a matching organization-owned repository. It lacks a security policy and security scanning, so maintenance and response practices are less transparent.
67%
Total Score
75
83
50
The package has 4 releases over about 19 months, but none in the last 12 months; the latest release was about 18 months ago. This makes ongoing maintenance uncertain.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. With no recent release activity either, this is evidence of currently limited maintenance.
Composer build tooling is present, but no security scanning tools are configured. The build setup is appropriate, while the missing scanning is a modest transparency gap.
No security policy was found in the repository. That does not show a security defect, but it reduces transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.0 || ^4.0 | — | — |
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
symfony/http-foundation Version ^5.0 || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.