It includes clear documentation, tests, release notes, and an MIT license, with organizational backing and no deprecation or archive status. The quiet recent commit period and unpinned workflow actions add maintenance and build-hygiene concerns.
76%
Total Score
75
100
88
75
The repository recorded zero commits and zero active maintainers during the last 3 months, which is a maintenance concern despite the recent release and push history.
Composer is used for builds, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
The linked repository is not archived and was pushed about 5 months ago, although that does not offset the lack of commits during the last 3 months.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 5 of 5 action references are unpinned; that weakens build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/varexporter Version ^0.6 | — | — |
laravel/framework Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.