The package includes a clear README, repository tests, a changelog, a license, and a security policy. Its workflow was fully audited with no high-confidence findings, but all four actions are unpinned. Monitor this young project closely before relying on it for long-lived compliance records.
62%
Total Score
50
86
83
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not offset by visible organizational handoff capacity.
This is a young package, 86 days old, with only one release and no established release cadence. That limits evidence of long-term maintenance, although the repository is active rather than abandoned.
One contributor made 100% of the two commits in the last three months. With a user-owned project and no second active contributor shown, maintenance depends heavily on one person.
Only two commits were recorded in the last three months, all during a very short project history. This is evidence of limited demonstrated maintenance capacity, though not yet of a collapsed or vanished project.
The repository uses Composer and Make, but no security scanning tool was detected. For a package handling consent and data-subject records, that is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.