58%
Total Score
caution
Usable with caveats: infrequent releases, no recent commits, and unpinned workflow actions limit confidence.
Only 3 releases have appeared over about 3 years and 9 months, with a median interval of about 19 months; just one release arrived in the last 12 months. This indicates slow maintenance.
There were no commits from active maintainers in the last 3 months, and the repository was last pushed about 7 months ago. This is a meaningful maintenance concern despite the recent release.
Composer build tooling is present, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
Version 0.0.3 is not a stable major release, so the public API may still change. It is not marked as a prerelease, which provides some compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4 | — | — |
eventsauce/backoff Version ^1.1 | — | — |
illuminate/database Version ^8|^9|^10|^11|^12 | — | — |
eventsauce/eventsauce Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.