Its licensing and documentation are clear, and the repository is an exact match with tests and release notes. Repository commits have been absent for three months, while all three workflow actions are unpinned and no security policy or scanning is present.
70%
Total Score
50
93
50
The package runs a post-autoload-dump install-time script. Composer lifecycle scripts are common for framework packages, but they add installation behavior that consumers should account for.
There were zero commits and zero active maintainers in the last three months. The recent release offsets this somewhat, but the lack of ongoing repository activity is a real maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP package this is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. This reduces transparency for reporting vulnerabilities, though it does not by itself indicate abandonment.
The only workflow was fully analyzed with no audit findings or untrusted-input sinks, and it avoids broad top-level write permissions. However, all three referenced actions are unpinned, leaving the workflow exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.1.0 | — | — |
illuminate/database Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/filesystem Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/collections Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0|dev-master | — | — |
php-http/client-common Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.