The MIT license, release notes, and small dependency set make the package straightforward to inspect and install. Its documentation and security-policy coverage are thin, so pin this version rather than relying on ongoing support.
56%
Total Score
0
100
88
83
The repository recorded zero commits and zero active maintainers during the last three months; with the last push nearly four months ago, ongoing maintenance appears to have stalled.
This release includes GitHub release notes for the exact version, which documents the change; however, the package has no README, reducing consumer-facing transparency.
Composer is used for builds, but no security-scanning tool is configured. The missing scanner is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, but not a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
halaxa/json-machine Version ^1.2 | — | — |
vicky-project/telegram-module Version ^1.1 | — | — |
joshbrw/laravel-module-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.