The package is small, correctly matched to its repository, MIT-licensed, and has no install-time scripts. Its single registry maintainer, absent security tooling, and zero commits in three months leave limited evidence of ongoing care despite two releases in the past year.
70%
Total Score
67
100
89
75
Only one account has registry publish access, which is a limited publishing base. The repository is organization-owned, so the registry count does not by itself establish that project backing is weak.
The repository had zero commits and zero active maintainers in the last three months. Two releases in the past year and a very recent push partly offset this, but the observed development activity remains thin.
The repository has four forks but zero stars and watchers. This provides little independent adoption evidence, though popularity is only supporting evidence and does not outweigh the release history.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance concern rather than evidence that the package is unsafe.
The repository has no security policy. For a small data-oriented library this is a limited gap, but it reduces the documented path for reporting issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
squirephp/countries Version self.version | — | — |
squirephp/repository Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.