The package includes tests, a usable README, and release notes for this version. Its missing license and fully unpinned workflow actions reduce transparency and supply-chain hygiene, while recent repository activity has not produced a new registry release.
48%
Total Score
75
64
50
The package has had no releases in the last 12 months, and its latest release was in April 2023 despite the source repository being updated more recently. This indicates the registry release line is effectively stalled.
No declared license, license file, or detected repository license is present. That leaves the legal terms for using this dependency unclear.
There were no commits and no active maintainers in the last three months. Although the repository has a recent push date, the measured activity still suggests maintenance may be intermittent.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the package is unsafe by itself.
The repository has no security policy. This weakens transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/url Version 2.2 | — | — |
vlucas/phpdotenv Version 5.5 | — | — |
guzzlehttp/guzzle Version 7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.