The package has a one-person publishing base and no security policy, while its tiny artifact offers little consumer documentation. The declared GPL-2.0-or-later conflicts with the detected GPL-3.0 license, so verify compatibility before adoption.
38%
Total Score
25
57
67
The package has had no release in more than four years, with zero releases in the last 12 months. Its six closely clustered releases provide little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing that development stopped in March 2022.
A license file is present, but it is detected as GPL-3.0 while the manifest declares GPL-2.0-or-later. This mismatch requires compatibility review before use.
Only one registry account has publish access. With no organization backing shown and no recent repository activity, this leaves the release dependent on a very thin publishing base.
The package contains only seven files and three source files, indicating a very small scope. That can be appropriate for a focused adapter, but it provides limited visible project context alongside the missing README.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/ray Version ^1.34 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.