Documentation, tests, changelog, licensing, and install behavior are well covered. Maintenance depends on one contributor, while workflow images are unpinned and the repository has no security policy.
70%
Total Score
67
94
83
The registry and repository are owned by the same individual account, confirming package ownership but providing no organizational handoff or redundancy.
All 38 recent commits came from one contributor, so maintenance continuity depends heavily on a single person despite the strong commit volume.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, making vulnerability reporting and response expectations less clear for a package handling database, network, and filesystem integrations.
The sole workflow was fully analyzed and has two high-confidence unpinned-image findings. The audit found no untrusted checkout, script injection, or broad top-level write permissions, so this is a hygiene caution rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^7.0 | — | — |
guzzlehttp/psr7 Version ^2.4 || ^3.0 | — | — |
illuminate/http Version ^13.0 | — | — |
illuminate/redis Version ^13.0 | — | — |
daverandom/libdns Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.