Usable with caveats: the release is current, stable, licensed, and not deprecated, but the linked repository shows no commits in three months and has no tests or security policy. The repository name does not match the package, so verify the source and maintenance ownership before adopting it.
58%
Total Score
50
100
78
67
A post-autoload-dump Composer lifecycle script is present. This is common for framework packages, but it adds install-time behavior that should be reviewed before use.
The artifact and repository include a README but neither contains tests or a changelog. For a package with substantial PHP and frontend code, the lack of visible tests reduces maintenance transparency and confidence.
The linked repository is owned by an individual user rather than an organization, so the three registry maintainers do not provide evidence of organizational backing; maintenance capacity remains uncertain.
The repository recorded zero commits and zero active maintainers in the last three months. This is a concrete maintenance concern despite the recent registry release.
The repository name does not match the package name, although its README mentions the package. The mention provides some linkage, but the mismatch still warrants verifying that this repository is the intended source.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^5.3|^6.0|^7.0|^8.0 | — | — |
laravel/sentinel Version ^1.0 | — | — |
laravel/framework Version ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
symfony/var-dumper Version ^5.0|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.