The package is well documented, licensed, tested in the repository, and clearly tied to its source. Its single-maintainer setup and missing security policy leave less oversight than mature alternatives.
62%
Total Score
33
100
94
50
The repository recorded zero commits and zero active maintainers in the last 3 months. Because this is a direct maintenance signal, it materially lowers confidence despite the recent release history.
Only one account has registry publishing access. That is a limited publishing base for an individually owned project and increases reliance on one person, although the repository shows substantial project maturity.
There are 11 open issues but no new or closed issues and no pull requests in the last month. This suggests limited recent interaction, though it is less concerning than a long-term absence of releases.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning reduces supply-chain hygiene, though it is not evidence that the package is unsafe by itself.
The repository has no SECURITY.md or other detected security policy. This leaves vulnerability-reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/regex Version ^2.0|^3.0 | — | — |
doctrine/dbal Version ^2.6|^3.5|^4.0 | — | — |
laravel/framework Version ^6.0|^7.0|^8.79|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.