Regular releases, a clear MIT license, tests, changelog, and a matching repository provide solid maintenance and transparency. Security documentation is absent, and recent work comes from one contributor, leaving limited backup if the maintainer stops.
78%
Total Score
67
100
94
83
The package and repository are both owned by the same individual account, so the source ownership is coherent. It does not provide organization-level succession or handoff support.
All five recent commits came from one contributor, so maintenance is concentrated and there is no demonstrated backup contributor. The active repository partly offsets this, but the concentration remains a real continuity risk.
Composer is used for builds, but no security-scanning tool is present. The missing scanner is a modest transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For a maintained library this leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
box/spout Version ^3.3 | — | — |
barryvdh/laravel-snappy Version ^1.0 | — | — |
tgalopin/html-sanitizer Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.