The repository is public, matches the package, includes tests, and has clear MIT licensing. Releases stopped nearly seven years ago, while repository activity stopped about three years ago; the lack of security scanning adds a smaller maintenance concern.
52%
Total Score
67
100
86
75
Only three releases were published, all around November 2019, with no release in nearly seven years. That makes compatibility and ongoing maintenance uncertain despite the repository remaining available.
There were zero commits and zero active maintainers in the last three months. Combined with the old latest release, this is meaningful evidence of stalled maintenance.
There were no new or closed issues and no merged pull requests in the last month, with one open pull request. This adds limited evidence of low current activity but is weaker than the release and commit history.
Composer is used as the build tool, but no security-scanning tool is configured. The missing scanner is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy. For a small Laravel parser this is a documentation gap, but it provides little evidence about abandonment compared with the stale release and commit activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^1.0 | — | — |
illuminate/support Version ^5.5|^6.0 | — | — |
illuminate/contracts Version ^5.5|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.