Tests, documentation, and licensing are in place, while the workflow is read-only and fully audited. Its two action references are unpinned, and there is no security policy or scanning tool.
64%
Total Score
67
86
75
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
The package is 49 days old and has only one release, so its maintenance record and compatibility track record are not yet established.
One contributor made all 4 commits in the last 3 months, leaving maintenance dependent on a single person and increasing abandonment or handoff risk.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance concern.
The repository has no security policy, leaving reporting and disclosure expectations undocumented for a package that handles encryption-related route keys.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jan2000/ffxradix Version ^1.1 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.