The repository is organization-owned and includes tests, a matching source tree, and a clear Apache-2.0 license. There is no security policy, and the project has no release or commit history beyond today.
68%
Total Score
75
100
88
67
This is the package's first release, published today, so there is no demonstrated release cadence or maintenance history yet.
There were no commits or active maintainers in the last three months, but the repository was only created and pushed today; this is mainly a lack of history rather than evidence of a collapsed project.
Composer is used as a build tool, but no security scanning tool is configured. The missing scanner is a modest transparency gap for a package with no other demonstrated maintenance history.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a hygiene concern, not evidence that the package is unsafe.
No workflows were present to audit, so there are no detected workflow risks; the lack of CI also means automated validation is not demonstrated.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tightenco/ziggy Version 2.6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.