The package includes a README, tests, and a matching organization-backed repository. Workflow references are not pinned, and recent release activity has not been followed by observed commit activity.
68%
Total Score
75
81
50
The package has existed for about 12 years with 54 releases and a latest release on February 23, 2026. Only one release in the last 12 months indicates limited recent cadence, despite the new release.
The repository recorded zero commits and zero active maintainers in the last three months. The release on February 23, 2026 provides some counterevidence, but current development activity is still unverified and weak.
Composer is used for the build, providing expected ecosystem tooling, but no security scanning tool is reported. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency but does not by itself make the release unfit.
Version 0.12.1 is not a stable-major release, so API compatibility may be less predictable. The long release history partly offsets this maturity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.10 | — | — |
laravel/framework Version ^10.0 | — | — |
laravel-doctrine/orm Version ^2.0 | — | — |
shapecode/doctrine-dbal-datetimeutc Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.