The package is clearly licensed, documented, and tied to an organization-owned repository. It has no repository security policy or automated security scanning, so ongoing oversight is limited.
70%
Total Score
75
93
50
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating that maintenance has paused since the latest release and increasing abandonment risk.
Composer is used for the build, but no security scanning tools are configured in the repository, reducing visible safeguards for dependency and source changes.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/url Version ^2.4 | — | — |
guzzlehttp/guzzle Version ^7.8.2 | — | — |
sharpapi/php-core Version ^1.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.