The package is licensed, documented, tested, and backed by an organization with a matching repository. Its zero repository commits in the last three months conflicts with five releases in about eight months, so maintenance evidence is mixed.
68%
Total Score
75
100
94
67
The package uses a post-autoload-dump install-time script. This is a potential installation side effect, but the signal does not show a dangerous script or unusual command.
The repository shows zero commits and zero active maintainers in the last three months, despite five releases in about eight months. This weakens confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. That is a modest repository hygiene gap rather than evidence that the package is unsafe to depend on.
The repository has no SECURITY.md policy. This limits the project's documented vulnerability-reporting process, although it does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.48.29|^11.0|^12.0|^13.0 | — | — |
sharpapi/php-core Version ^1.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.