The repository has tests, a changelog, a security policy, and static analysis. Its MIT licensing and lack of install-time scripts are reassuring, but unpinned workflow actions weaken build hygiene.
15%
Total Score
0
50
83
Packagist marks the entire package as abandoned and provides no replacement package, which is a severe adoption risk for a dependency.
The package has had no releases in the last 12 months, and its latest release was on February 15, 2023, indicating prolonged inactivity.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package's prolonged lack of releases.
The artifact includes a substantial README, changelog, and release notes, while the repository has tests and a changelog. The README also explicitly describes the project as a developer preview and advises against production use.
The repository name does not match the package name and its README does not mention the package, leaving some uncertainty about whether the linked source repository directly belongs to this release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/intl Version ^4.3|^5.0|^6.0 | — | — |
doctrine/dbal Version 2.11.* | — | — |
dompdf/dompdf Version ^0.8.0 | — | — |
nesbot/carbon Version ^2.0 | — | — |
illuminate/log Version ^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.