The package includes a usable README and a small, transparent file tree. Its declared MIT license conflicts with the detected Apache-2.0 license, and the repository has no security policy or scanning tools.
38%
Total Score
25
100
72
88
This is the package's only release, published in May 2019, with no releases in the last 12 months. That long period without a new release is a strong abandonment concern.
There were no commits and no active maintainers in the last three months. Combined with the single 2019 release, this indicates an effectively inactive project.
A license file is present, so the release is licensed, but the manifest declares MIT while the artifact and repository license file are detected as Apache-2.0. This mismatch reduces transparency.
The repository is owned by an individual rather than an organization. This does not prove poor maintenance, but it offers less visible backing for a project that has been inactive for years.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide no evidence of a broad user or contributor base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
illuminate/support Version 4.*|5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.