The package is clearly licensed and the source repository contains a README and a substantial test suite. Its small dependency footprint and straightforward Composer build are helpful, but they do not offset the project's inactive status.
12%
Total Score
0
40
50
Packagist marks the entire package as abandoned, with no replacement package specified. This is a direct warning against taking a new dependency on the release.
The package has 20 releases, but its latest release was about 3 years and 2 months before collection and it had no releases in the preceding 12 months. That strongly indicates abandonment despite its earlier release activity.
The repository had no commits and no active maintainers in the last 3 months. This confirms that the abandonment concern is reflected in actual project activity, not just registry metadata.
The linked repository is archived, so it is no longer maintained through the normal source workflow. Its last push was about 2 years and 10 months before collection, leaving little prospect of fixes or compatibility updates.
The single workflow has no untrusted checkout or script-injection findings, but it uses a top-level write token and its one action reference is unpinned. These are hygiene concerns, not the main reason to reject the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^6.0 || ^7.0 || ^8.0 || ^9.0 | — | — |
dragon-code/support Version ^5.0 | — | — |
cashier-provider/core Version ^3.0 | — | — |
dragon-code/contracts Version ^2.0 | — | — |
dragon-code/simple-dto Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.