Its very small artifact is easy to inspect, and the organization-owned repository matches the package. The MIT declaration and lack of install-time scripts reduce adoption friction; limited security tooling is the main remaining weakness.
78%
Total Score
83
100
94
83
There were no commits and no active maintainers in the three months before collection. The same-day release and repository push compensate for this short quiet period, but the recent development base is thin.
Composer build tooling is present, but no security-scanning tools were detected. For a tiny data package this is a limited transparency weakness rather than a severe adoption blocker.
The repository has no published security policy. This slightly reduces transparency for reporting vulnerabilities, though the package's small, narrowly scoped artifact limits the practical impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
squirephp/countries Version self.version | — | — |
squirephp/repository Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.