The README, MIT declaration, stable releases, and organization ownership give consumers clear usage and continuity context. Composer-only dependencies keep the package focused, while the install script merits ordinary deployment scrutiny.
68%
Total Score
83
94
50
A post-autoload-dump script runs during Composer installation, adding execution during setup; this is a modest supply-chain and deployment consideration without evidence of harmful behavior.
Only one commit was recorded in the last 3 months, indicating limited recent development activity despite the recent release history.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest verification gap for a package that calls an external API.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.48.29|^11.0|^12.0|^13.0 | — | — |
sharpapi/php-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.