The package includes tests, a substantial README, release notes, and an active organization-owned repository. Its long release interval and one-contributor recent activity leave maintenance capacity thinner than ideal, while the workflow has no high-severity findings but uses one unpinned action.
68%
Total Score
67
86
83
Only two releases have been published across 786 days, with one release in the last 12 months and a median interval of about 765 days. The recent release is positive, but the overall cadence is slow for a dependency.
One contributor made all recent commits, creating concentrated maintenance risk. Organization ownership provides some handoff capacity, so this is a caution rather than a severe risk.
The repository had only one commit in the last three months, indicating limited recent development activity. The recent release and organization backing provide some compensation, but not for the thin maintenance pace.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest process gap rather than evidence of abandonment.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, and it does not grant top-level write permissions. Its one action is unpinned, which is a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^9.4.5 | — | — |
teamtnt/tntsearch Version ^4.0 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.