Usable with caveats: the package has clear organization backing, tests, release notes, and a matching repository, but maintenance has recently gone quiet. Install-time automation and permissive workflow settings also warrant review before adopting it broadly.
62%
Total Score
63
100
88
60
The repository recorded zero commits from any active maintainer in the last three months, a concrete sign of recently stalled maintenance and the main adoption concern.
One workflow uses pull_request_target for Dependabot auto-merge, which carries elevated workflow risk, though no untrusted checkout or script-injection patterns were detected.
The package uses a post-autoload-dump install-time script, which adds execution during installation and deserves review, although one standard Composer lifecycle hook is not by itself a severe concern.
The package has 19 releases since January 2023, but only one release in the last 12 months, indicating a slower recent release cadence despite an established history.
There are no open issues and two open pull requests, but no issues or pull requests were merged in the last month, offering limited evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
open-telemetry/api Version ^1.4 | — | — |
open-telemetry/sdk Version ^1.7 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
open-telemetry/sem-conv Version ^1.36 | — | — |
php-http/guzzle7-adapter Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.