The package is small and clearly identified, with an MIT license, a focused dependency set, and no install-time scripts. Its source has seen no commits since April 2020, and one registry maintainer leaves little evidence of ongoing support.
42%
Total Score
33
100
75
83
Only three releases appeared, all concentrated around April 2020, with no releases in the following six years. This strongly suggests the package is no longer actively maintained.
There were zero commits and zero active maintainers during the last three months, consistent with roughly six years without source updates. This is strong evidence of abandonment risk.
One registry account has publish access, providing a thin apparent publishing base. The repository is user-owned rather than organization-backed, so there is little provided evidence of broader maintenance capacity.
The repository owner is an individual account, not an organization, and no broader project backing is shown. Combined with the single maintainer and inactive repository, this weakens confidence in continuity.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest transparency gap, secondary to the lack of recent development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.