The package is clearly identified, licensed, documented, and has no install-time scripts. Its small project footprint provides limited evidence for long-term maintenance; pin this version and test it against your Laravel upgrade path.
57%
Total Score
50
100
88
83
The repository is owned by an individual user rather than an organization. Combined with the single-contributor activity, this provides limited visible maintenance backing.
Only one release exists, published about 13 months ago, with no releases in the last 12 months. This limits evidence of ongoing maintenance and compatibility work.
One contributor made all commits during the last three months, leaving no demonstrated contributor redundancy. The repository is user-owned, so there is no organization backing shown to offset that concentration.
Only one commit was recorded in the last three months from one active maintainer. The recent activity is positive, but the very low volume gives limited evidence of sustained maintenance.
Composer is used as the build tool, but no security scanning tools were detected. For a small package this is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.