The package has a clear README, MIT licensing, and a manageable three-runtime-dependency footprint. Its recent activity is concentrated in one contributor, with no security policy or repository security scanning, so future maintenance deserves scrutiny.
62%
Total Score
50
100
93
75
The repository is owned by a user account rather than an organization. Combined with the one-contributor activity profile, there is no observed organizational handoff capacity to offset the concentrated maintenance base.
One contributor made 100% of the two commits in the last 3 months. This creates a meaningful continuity risk because the observed maintenance base is concentrated in one person.
Only 2 commits were recorded in the last 3 months. That is some recent activity, but it is a thin maintenance signal for a package with 11 releases in the last year.
Composer is used for builds, but no security scanning tools are configured. The missing scanning reduces transparency around routine security checks, though it is not evidence of a defect by itself.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, which is a modest transparency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.0 | — | — |
hidehalo/nanoid-php Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.