A clear README, tests, release notes, and matching organization repository support adoption. The single registry maintainer and absent security policy leave limited review depth.
74%
Total Score
67
100
93
67
A post-autoload-dump install-time script is present. This is a mild transparency and installation-complexity concern, but the signal alone does not indicate unsafe behavior.
Only one registry account has publishing access. The organization-owned repository provides some backing, but the registry publishing base remains narrow.
No commits or active maintainers were recorded in the last three months, despite a repository push today and recent releases; this creates uncertainty about ongoing development depth.
Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.48.29|^11.0|^12.0|^13.0 | — | — |
sharpapi/php-core Version ^1.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.