The source repository includes tests and this release has specific release notes. Three contributors made 14 commits in three months, while the organization backing reduces the risk from one registry publisher. The workflow has no dangerous findings, but its single action is unpinned and the repository has no security policy.
86%
Total Score
100
93
75
Composer build tooling is present, but no security-scanning tool was detected. That is a minor assurance gap because other maintenance evidence is strong.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a modest transparency gap, not evidence of abandonment.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. Its one action is unpinned, which weakens reproducibility and merits a minor caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^4.2 | — | — |
laravel/framework Version >=11 | — | — |
ronasit/laravel-helpers Version >=3.5 | — | — |
winter/laravel-config-writer Version >=1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.