The package is licensed, documented, tested, and released on a steady cadence. Organization backing and a matching repository help, but no commits were recorded in the last three months, and no security policy or scanning tools are reported.
68%
Total Score
75
100
94
67
The package runs a Composer post-autoload-dump script during installation. This is an additional execution surface, though the signal does not show a harmful script or unusual behavior.
The repository recorded zero commits and zero active maintainers in the last three months. Recent registry releases and a current repository push partly offset this, but the absence of development activity raises maintenance risk.
Composer build tooling is present, but no security scanning tools are reported. This is a transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented, although the package's tests, license, and release notes provide other useful project documentation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.48.29|^11.0|^12.0|^13.0 | — | — |
sharpapi/php-core Version ^1.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.