It includes tests, a README, release notes, and an MIT license, while the repository still matches the package. Its dependencies and install-time scripts deserve extra review because the project has no recent maintenance.
30%
Total Score
0
50
75
50
The latest release was about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package intended as an application dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.
Seven runtime dependencies, including Laravel, JWT, Entrust, and Baum, create meaningful compatibility and maintenance exposure for this old package, though the count itself is not excessive.
The package declares five Composer lifecycle scripts, including install and update hooks. Their presence increases installation complexity and warrants review, especially because the project is no longer actively maintained.
Composer build tooling is present, showing a defined build path, but no security scanning is configured. This provides limited positive evidence and does not compensate for the project's age.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
baum/baum Version ~1.1 | — | — |
doctrine/dbal Version ^2.5 | — | — |
tymon/jwt-auth Version 0.5.* | — | — |
zizaco/entrust Version dev-laravel-5 | — | — |
laravel/framework Version 5.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.