The package includes extensive documentation and tests, with a release note for this version. Install-time scripts and a broad dependency set add operational complexity, so plan ownership carefully.
73%
Total Score
75
50
94
50
The package declares 20 runtime dependencies, spanning framework, HTTP, mail, parsing, and utility components. This breadth increases update and compatibility exposure compared with a narrowly scoped library.
The package runs post-install and post-update Composer scripts. These scripts increase installation-time behavior and maintenance risk, even though the signal does not show that they are malicious.
All 38 recent commits came from one contributor, giving the project a bus factor of one. The active release and commit cadence helps, but there is no demonstrated handoff capacity.
Composer is used for builds, but no security scanning tools were detected. The missing scanning layer is a modest transparency and maintenance gap, not evidence of unsafe code.
The repository has no security policy. This leaves vulnerability reporting and response expectations unclear for a package with broad runtime functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.15 | — | — |
cocur/slugify Version ^4.2.0 | — | — |
meyfa/php-svg Version * | — | — |
illuminate/http Version * | — | — |
symfony/console Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.