The linked project remains maintained, with repository tests, release notes for this version, and a security policy. Use laravel-lang/publisher instead, which is the listed replacement.
20%
Total Score
50
67
75
Packagist marks the entire package as abandoned and explicitly names laravel-lang/publisher as its replacement. This is a severe adoption risk for a new dependency.
The registry shows no releases in the last 12 months and lists the latest release as more than four years old, despite the assessed version being stable. This weakens confidence in the published package.
The repository recorded zero commits and zero active maintainers in the last three months. Although the repository is not archived, this indicates currently weak observable maintenance activity.
All six workflows were analyzed with no audit findings, but all eight action references are unpinned and four workflows grant top-level write permissions. These are workflow hygiene concerns, not a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-lang/lang Version ^10.1.9 | — | — |
illuminate/console Version ^7.0|^8.0|^9.0 | — | — |
illuminate/support Version ^7.0|^8.0|^9.0 | — | — |
illuminate/contracts Version ^7.0|^8.0|^9.0 | — | — |
dragon-code/contracts Version ^1.21.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.