The repository is backed by an organization, includes tests, and published release notes. Only one contributor made one commit in the last three months, while the workflow uses three unpinned actions and has no security policy.
78%
Total Score
67
100
89
50
All recent commits came from one contributor with a 100% share. Organization backing partly compensates for this concentration, but recent hands-on maintenance remains narrow.
Only one commit was recorded in the last three months, by one active maintainer; this is limited recent maintenance and lowers confidence in rapid ongoing support.
The repository has zero stars and forks and one watcher. Popularity is supporting evidence only, so this modest visibility slightly limits external validation but is not independently concerning.
Composer build tooling is present, but no security-scanning tool was detected. For a maintained package this is a transparency and defense-in-depth gap, not evidence of unsafe code.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, which is a maintenance transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0|^3.0 | — | — |
illuminate/queue Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
lorisleiva/cron-translator Version ^0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.