Clear documentation, tests, changelog, and an MIT license make adoption straightforward. The two-person project has limited security tooling, and all four workflow actions are unpinned, so build reproducibility is weaker.
82%
Total Score
83
90
50
Two contributors were active in the last 3 months, although one made 8 of 11 commits. The second active contributor partly compensates for the concentration, making this a minor concern rather than a severe bus-factor risk.
Composer build tooling is present, but no security scanning tools were detected. That weakens automated assurance modestly while the repository's tests and ongoing commits provide some compensation.
No repository security policy was found. This is a transparency gap for a package processing live network events, though it is not evidence of unsafe code by itself.
Both workflows were fully analyzed with no untrusted checkouts, script injection, or high-severity findings, and no workflow has top-level write permissions. However, all 4 action uses are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ratchet/pawl Version ^0.4 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
react/event-loop Version ^1.5 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.