Clear documentation, licensing, and release notes improve confidence. The remaining automation review is incomplete, so adopt with normal change-control rather than treating it as a low-risk default.
63%
Total Score
67
100
94
100
The repository recorded zero commits and zero active maintainers during the last three months. Although the release was recently pushed, the lack of broader recent commit activity lowers maintenance confidence.
There were no new or closed issues and no merged pull requests in the last month, while 15 issues remain open. This indicates limited recent project interaction.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and preventive-maintenance gap.
All 10 analyzed action references are unpinned, and the audit found a high-confidence bot-condition issue in a pull_request_target workflow. The audit is also incomplete because only 4 of 5 workflows were analyzed; no untrusted checkout or script-injection sink was found, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dotenv Version ^6.0 || ^7.0 | — | — |
guzzlehttp/guzzle Version ~7.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.