Usable with caveats: the package is well-structured, tested, clearly licensed, and backed by the Corcel organization, but its latest release was nearly six years ago and there has been no recent commit or issue activity. Depend on it only if its older Laravel and PHP compatibility fits your project.
62%
Total Score
67
100
88
90
The package has a substantial history with 22 releases, but its latest registry release was on October 31, 2020, with no releases in the last 12 months. This is a meaningful maintenance and compatibility risk.
There were no commits and no active maintainers during the last three months. Combined with the old latest release, this raises a clear risk that bugs and compatibility problems may remain unattended.
The repository has 27 open issues and 13 open pull requests, but no issues or pull requests were opened, closed, or merged in the last month. This suggests limited current maintenance capacity.
Composer is used for the build, providing expected ecosystem tooling, but no security-scanning tools are configured. The missing scanning is a transparency gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. This modestly reduces vulnerability-reporting transparency, although the absence of workflows and the package's small, focused scope limit the significance of this gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jgrossi/corcel Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.