Clear documentation, an MIT license, release notes, and a matching repository make adoption easier. The project is small, has no security policy or scanning, and its workflow dependencies are not pinned.
58%
Total Score
75
100
79
50
A post-autoload-dump install script is present. This is an additional execution surface, but the signal does not show harmful behavior or make the package unfit on its own.
The package has 8 releases over about 2 years, but none in the last 12 months; that recent pause raises maintenance risk despite the earlier release history.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which supports concern that development has stalled.
Composer build tooling is present, but no security scanning tools were detected; this is a hygiene gap rather than evidence of an unsafe release.
The repository has no security policy, leaving disclosure and response expectations undocumented for a package that handles application content and translation credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
deeplcom/deepl-php Version ^1.1 | — | — |
aws/aws-sdk-php-laravel Version ^3.10 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
stichoza/google-translate-php Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.