The package is clearly documented, licensed, and free of install-time scripts. Its maintenance base is thin, with only two releases overall and all recent repository work from one contributor; there is also no security policy.
64%
Total Score
50
88
75
Only one registry account can publish releases. Because the repository is user-owned rather than organization-owned, this reinforces the project's limited maintenance capacity.
Only two releases have been published since December 2020, with one release in the last 12 months and a median interval of about 5.6 years. The recent release helps, but the long gaps indicate limited release continuity.
All recent commits came from one contributor, leaving maintenance dependent on a single active person.
There was one commit in the last three months, so the repository is not inactive, but the very low activity provides limited evidence of sustained maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.372 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
aws/aws-php-sns-message-validator Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.