Clear licensing and a documented installation path reduce adoption friction. Recent repository work is limited to two commits in three months from one contributor, though the organization-backed project continues releasing regularly.
78%
Total Score
67
100
94
100
One contributor made all two commits during the last three months, leaving recent development activity concentrated in a single person; organization backing partly offsets the handoff risk.
Only two commits were recorded in the last three months, indicating modest recent engineering activity despite the regular release history.
Composer is used for builds, but no repository security-scanning tools were detected. This is a modest transparency gap rather than evidence of abandonment.
The single workflow is fully analyzed and has no audit findings or untrusted checkout/script-injection paths. Its one action is unpinned, which is a minor reproducibility concern, while the pull_request_target trigger is not risky without a corresponding sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
php-flasher/flasher Version ^2.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.