Its stable version, MIT license, repository tests, and release notes provide useful maintenance and transparency evidence. The roughly six-year gap since the last release and commit activity makes abandonment a substantial risk.
45%
Total Score
0
81
50
The latest release was published in May 2020, with no releases in the last 12 months. A roughly six-year release gap is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no observed ongoing maintenance.
Composer is used for builds, but no security scanning tools were detected. For an old package with no recent activity, the missing automated security coverage increases maintenance concern.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear. This adds a transparency gap, though it is less significant than the absence of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^5.3|^6.0|^7.0 | — | — |
illuminate/support Version ^5.3|^6.0|^7.0 | — | — |
symfony/dom-crawler Version ^2.7|^3.0|^4.0 | — | — |
symfony/css-selector Version ^2.7|^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.