There is no security policy or automated security scanning, and installation runs a post-install command. The release is documented, tested, licensed, and linked to a matching non-archived repository, but its small maintainer base and stalled activity increase upkeep risk.
58%
Total Score
50
83
50
The package runs a post-install command, adding install-time behavior that deserves review and increases dependency-management complexity.
One registry maintainer is consistent with a small project, but it leaves limited visible publishing capacity when combined with the inactive repository.
Only two releases have appeared since July 2023, with no release in roughly two years after the July 2024 version. This weakens confidence in ongoing maintenance for a framework package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating stalled development.
Composer build tooling is present, but no security-scanning tool was detected, leaving automated vulnerability checks absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.53.1 | — | — |
optimus/onion Version ~1.0 | — | — |
voku/anti-xss Version ^4.1 | — | — |
fakerphp/faker Version ^1.16 | — | — |
josantonius/json Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.