The README clearly identifies this as a Composer metapackage and explains how to consume it. Apache-2.0 licensing, organization ownership, and a matching repository improve transparency, but the package has little operating history to establish dependable maintenance.
67%
Total Score
75
100
80
50
This is the package's first release, published 0 days ago, so there is no release cadence or history demonstrating sustained maintenance. Its clear purpose as a generated type-definition metapackage partly explains the limited history, but does not remove the uncertainty.
The repository has 0 commits and 0 active maintainers in the last 3 months, which is consistent with a newly generated package but provides no evidence of ongoing maintenance capacity.
The repository uses Composer for builds, which fits this PHP metapackage, but it has no reported security-scanning tooling. That is a modest transparency and hygiene gap rather than a severe concern for this small artifact.
No security policy is present in the repository. For a tiny metapackage this is a limited gap, but it leaves vulnerability-reporting expectations unspecified.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/psalm-plugin-laravel-impl Version ~4.16.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.