The workflow leaves two actions unpinned, and the repository has no security policy or scanning. The MIT license, clear README, small dependency set, and organization backing improve transparency.
58%
Total Score
75
100
78
75
The package includes a substantial README, while its lack of bundled tests and changelog is normal packaging practice. The repository has no tests or changelog, but that is a modest transparency weakness rather than a severe dependency risk.
The package is about 800 days old with 9 releases, but only 1 release in the last 12 months. The very short median interval suggests earlier release bursts rather than a consistently active cadence.
The repository recorded 0 commits and 0 active maintainers during the last 3 months. Although the recent release push shows some activity, the short-term maintenance signal is weak.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these numbers provide little independent evidence of maturity or community support.
Composer is used for builds, but no security scanning tools are configured. The missing scanning reduces maintenance hygiene evidence without showing that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.8|^6.0|^7.0|^8.0|^9.0|^10|^11|^12|^13 | — | — |
webpatser/laravel-uuid Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.