It has a clear license, useful documentation, stable versioning, and organization-backed ownership. Its short release history and limited project activity leave ongoing maintenance less proven.
70%
Total Score
75
100
88
50
A post-autoload-dump install script is present. This adds some installation-time behavior, but the provided signal does not indicate that it is unusually risky or excessive.
The package is young at 227 days, with three releases and a median interval of about 27 days; this shows some release activity but limited long-term history.
The repository recorded zero commits and zero active maintainers during the last three months. Although the package had a recent release, this leaves ongoing maintenance capacity uncertain.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, reducing clarity about how vulnerabilities are reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.48.29|^11.0|^12.0|^13.0 | — | — |
sharpapi/php-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.