The package includes tests, a README, and a matching source repository, but its installation hooks add maintenance and supply-chain complexity. The missing license and minimal security practices make long-term adoption harder to justify.
35%
Total Score
64
67
Only two releases exist, both dating to July 2013, with no release in roughly 13 years. This is strong evidence of abandonment for a package intended to support project initialization.
The package declares no license and contains no license file; the linked repository also has no license file. This leaves developers without clear permission to use or redistribute it.
Composer runs post-create, post-install, post-update, and pre-update scripts. These hooks increase installation and update complexity and deserve extra trust in an otherwise very old package.
Composer is used for builds, but no security-scanning tooling is present. This is a hygiene gap rather than proof of unsafe code, and it reinforces the limited maintenance evidence.
The repository has no security policy. For a small, inactive project this reduces transparency about reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 4.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.