Tests, a changelog, a clear MIT license, and a focused dependency set improve confidence for consumers. The organization-backed repository has no security policy or scanning, and recorded commits were absent in the last three months.
68%
Total Score
83
100
89
75
The package uses a post-autoload-dump install-time script, which adds execution during Composer installation and warrants attention, but is not severe on its own.
No commits and no active maintainers were recorded in the last three months. The same-day repository push and recent release history partly offset this, but the short-term development lull remains a maintenance concern.
The repository has one star, no forks, and no watchers, showing limited community adoption. Organization backing and the package's recent release activity provide some compensation, so this is supporting caution rather than a major risk.
Composer build tooling is present, but no security scanning tools are reported, leaving a security-hygiene gap in the source project.
The repository has no security policy, so users lack a documented channel and process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.48.29|^11.0|^12.0|^13.0 | — | — |
sharpapi/php-core Version ^1.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.