The release has a clear GPL license, a usable README, repository tests, and no install-time scripts. Its large runtime dependency set increases upkeep burden, while the repository lacks security scanning and does not mention the package in its README.
32%
Total Score
0
50
63
83
The latest release was on June 12, 2019, with no releases in the last 12 months. More than seven years without a release is strong evidence of abandonment risk, despite 38 historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no observed ongoing maintenance.
The package declares 36 runtime dependencies, including a broad Laravel and Symfony component set. That breadth increases compatibility and maintenance exposure for an inactive framework.
The repository name matches the package, reducing the risk of an unrelated source repository, but its README does not mention the package. That leaves a modest ownership and publication-transparency concern.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these low adoption indicators provide no compensating evidence for the lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0 | — | — |
filp/whoops Version ^2.1 | — | — |
ramsey/uuid Version ^3.8 | — | — |
illuminate/bus Version ^5.8 | — | — |
illuminate/log Version ^5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.