Usable with caveats: the package is actively released, stable, licensed, and backed by a matching organization repository. However, there have been no commits or active maintainers in the last three months, and the repository has no security scanning or policy, so verify that its current behavior meets your needs.
68%
Total Score
50
100
89
75
There were zero commits and zero active maintainers in the last three months, despite two registry releases in the last year. This is the clearest maintenance concern and raises abandonment risk if the package needs fixes.
The package runs a post-autoload-dump install-time script. This adds execution during installation and deserves review, although the signal does not show that the script is malicious or unusually dangerous.
There were no new or closed issues or pull requests in the last month, and no pull requests were merged. This provides little evidence of active community maintenance, though open issue count is unknown.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for community scrutiny, but popularity alone does not establish that a small package is unhealthy.
The repository uses Composer, but no security scanning tools were detected. Build support is present, while automated security oversight is limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/log Version ^10|^11|^12|^13 | — | — |
monolog/monolog Version ^3.6 | — | — |
phpgenesis/common Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.