Recent releases and a matching, well-tested source tree add useful confidence. The main limitations are concentrated recent activity, no security policy or scanning, and unpinned workflow actions.
78%
Total Score
67
94
50
The package runs a post-autoload-dump install-time script, which adds a modest execution concern even though only one standard Composer lifecycle hook is present.
All recent commits came from one contributor. Organization backing provides some handoff capacity, but no second recently active contributor is shown.
Only 2 commits were recorded in the last 3 months, which is modest activity, though the repository was recently updated and the release history remains active.
The project uses Composer and Make, but no security scanning tools were detected, leaving a maintenance and security-process gap.
The repository has no SECURITY.md or other detected security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
patchlevel/event-sourcing Version ^3.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.