Documentation is extremely thin and the repository has no published security policy. Organization backing, a current repository push, a small dependency set, and a clean workflow audit provide useful safeguards; pin 1.0.3.
70%
Total Score
100
100
83
50
A README is present but only 47 characters and provides almost no usage guidance. The absence of packaged tests and a changelog is normal for an artifact and is not penalized.
The repository has zero stars, forks, and watchers, offering no external adoption evidence. Popularity is supporting evidence only, so this is a minor concern rather than a decisive risk.
Composer is used as a build tool, but no security-scanning tool is present. That is a modest repository-hygiene gap, not a severe dependency risk by itself.
The repository has no published security policy, leaving reporting and response expectations unclear for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ~4.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.