This is a healthy, actively maintained release with a long history dating to 2017, 175 releases, 19 releases in the last 12 months, and a latest release published very recently. The linked repository is active, non-archived, organization-backed, correctly associated with the package, and shows substantial recent activity from three contributors, with tests and GitHub Releases providing useful development transparency. The main concerns are that the package artifact lacks a README and changelog, the repository has no security policy or configured top-level workflow permissions, and no security-scanning tooling was detected; these are hygiene and process gaps rather than evidence of abandonment, and the repository's tests and documentation partially compensate for the artifact-level omissions.
88%
Total Score
100
100
94
80
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning capability is a process gap, though it does not outweigh the strong maintenance evidence.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a transparency gap for a maintained package.
The only workflow lacks top-level permissions declarations. No top-level write permissions were detected, but explicit least-privilege configuration would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^4.2 | — | — |
guzzlehttp/guzzle Version ^7.9.2 | — | — |
laravel/framework Version >=11.0 | — | — |
php-mock/php-mock-phpunit Version ^2.10 | — | — |
riverline/multipart-parser Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.