It has a clear MIT license, a documented tree, and repository tests. Its large dependency surface and absent security policy add maintenance burden.
10%
Total Score
0
50
40
50
Packagist marks the entire package as abandoned, with no replacement package supplied. This is a direct warning against taking a new dependency on it.
The package has had no releases in nearly six years despite 38 historical releases. Its earlier cadence shows past activity but does not offset the prolonged halt.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with its archived state, this indicates abandonment rather than a short maintenance pause.
The linked repository is archived and was last pushed over four years ago, so ongoing fixes and support are unlikely.
The package declares 23 runtime dependencies, creating a broad compatibility and maintenance surface for a package that is no longer actively released.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cortex/auth Version ^7.0.0 | — | — |
league/fractal Version ^0.19.0 | — | — |
silber/bouncer Version v1.0.0-rc.10 | — | — |
illuminate/auth Version ^8.0.0 || ^9.0.0 | — | — |
illuminate/http Version ^8.0.0 || ^9.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.