Usable with caveats: the package is backed by a matching, tested repository and is not archived, but it has had only one release and no commits or releases for about 18 months. Limited adoption, no security scanning, and an install-time script add maintenance and review concerns.
52%
Total Score
75
81
70
The package runs a post-autoload-dump lifecycle script during installation. This is not inherently unsafe, but it increases installation complexity and warrants review before use.
This is the package's only release, published about 18 months ago, with no releases in the last 12 months. That provides little evidence of sustained maintenance.
The repository recorded no commits and no active maintainers during the last 3 months, consistent with the long release gap. The repository is not archived, but current maintenance activity is unproven.
The repository has 0 stars and 0 forks, with only 2 watchers. Popularity is not decisive, but this offers little supporting evidence of broad use or community review.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency gap for a dependency with little maintenance and adoption evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
psr/http-message Version ^2.0 | — | — |
laravel/framework Version ^11.15|^12.2 | — | — |
hamidrezaniazi/pecs Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.