Documentation, licensing, and release notes make integration straightforward. The organization-backed repository is intact and the assessed release is recent, but no commits were recorded in the last three months, security scanning is absent, and workflow actions are unpinned.
68%
Total Score
75
50
94
75
The release declares 11 runtime dependencies, including several framework and geocoding components. This is a meaningful integration surface, though the signal does not show an unsafe or unusually excessive dependency pattern.
No commits and no active maintainers were recorded in the last three months. The recent release and repository push partly compensate, but this still indicates limited current development activity.
There were no newly opened or closed issues in the last month and no pull requests merged, with 22 issues still open. This suggests limited recent project activity, although one pull request was opened.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency for a package with multiple runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
react/promise Version ^2.8 || ^3.0 | — | — |
symfony/console Version ^4.4 || ^5.0 || ^6.0 || ^7.0 | — | — |
react/event-loop Version ^1.0 | — | — |
php-http/discovery Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.