The Laravel Framework.
42%
Total Score
unhealthy
Risky: no releases or commits in about four years, despite documentation and tests.
The package defines four Composer lifecycle scripts, which require extra installation trust and operational review, although such scripts can be normal for a Laravel application.
The package has had only two releases, with none in the last four years, indicating a strong abandonment concern despite the short initial release interval.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and materially increasing abandonment risk.
The repository is not archived, but its last push was about four years ago; the unarchived status does not compensate for the observed inactivity.
The linked repository has no security policy, leaving vulnerability reporting and disclosure expectations unclear for an application handling accounts and files.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.7 | — | — |
laravel/sanctum Version ^3.0 | — | — |
kalnoy/nestedset Version ^6.0 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
laravel/framework Version ^9.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.