The package has a useful README, tests, a matching source repository, and an MIT declaration. Install-time scripts, absent security scanning, and no security policy add maintenance and review overhead.
35%
Total Score
0
75
67
The package has only one release, published about 8 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a framework extension, despite the absence of registry deprecation.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its last push being about 8 years ago. This is a severe abandonment signal for a package intended to underpin applications.
The package runs post-autoload-dump, post-create-project-cmd, and post-root-package-install scripts. These increase installation complexity and the amount of package code executed during setup, creating a modest dependency risk.
Composer is used for builds, but no security scanning tools are configured. That weakens transparency around dependency and source risks, though it is secondary to the clear inactivity.
The repository has no security policy. This reduces clarity about vulnerability reporting and response expectations, adding a transparency gap for a framework extension.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ~1.0 | — | — |
symfony/config Version ^4.0 | — | — |
fideloper/proxy Version ~4.0 | — | — |
laravel/framework Version 5.6.* | — | — |
jenssegers/mongodb Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.