The codebase is small, with four runtime dependencies and no install-time scripts. It has no README, tests, changelog, security policy, or security scanning, leaving little evidence for safe long-term maintenance.
35%
Total Score
0
100
75
75
The package has had no release in nearly seven years: its latest of six releases was published in September 2019, with none in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since September 2019.
The artifact has no README, which makes a library harder to integrate and reduces consumer-facing transparency. The absence of tests and a changelog is normal for published artifacts and is not penalized here.
Composer is used for the build, which is appropriate, but no security-scanning tool is configured. Combined with the long inactivity period, this leaves dependency and code-risk checks unsupported.
The linked repository has no security policy, so there is no documented process for reporting or handling vulnerabilities in this framework.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ^2.5 | — | — |
jenssegers/blade Version ^1.2 | — | — |
rakit/validation Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.