Its license, repository tests, and long history provide useful maintenance context. The project directs new users to a successor and limits this package to bug fixes, while recent repository activity is absent; use the successor for new work.
45%
Total Score
67
83
50
The README explicitly calls this package legacy, says not to use it for new projects, and directs users to laravel-json-api/laravel. Repository tests and a changelog provide some compensating transparency, but the package is no longer developed for new features.
The repository has 0 commits and 0 active maintainers in the last 3 months. The recent release and stated bug-fix-only maintenance soften this as abandonment evidence, but do not remove the concern for a new dependency.
There were no new or closed issues or pull requests in the last month, with 27 open issues and no open pull requests. This supports the picture of limited ongoing development.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. The package's clear license and repository documentation compensate for general transparency but not this security-process gap.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all 3 action references are unpinned. That is a supply-chain hygiene weakness rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
ramsey/uuid Version ^4.0 | — | — |
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
symfony/psr-http-message-bridge Version ^7.0 | — | — |
laravel-json-api/neomerx-json-api Version ^5.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.