The matching repository, MIT license, and release notes provide basic transparency. Unpinned workflow actions and no security policy add smaller maintenance concerns.
10%
Total Score
0
42
50
Packagist marks the entire package as abandoned, with no replacement supplied. This is a direct warning against taking a new dependency on it.
This release was published about 2 years and 4 months ago, and it is the package's only release; there have been no releases in the last 12 months. That is strong abandonment evidence.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the archived state and lack of ongoing maintenance.
The linked source repository is archived, and its last push was about 2 years and 3 months ago. Archived source strongly indicates the project is no longer maintained.
The repository has no security policy. This is a transparency and maintenance gap, though it is secondary to the package's abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11 | — | — |
guzzlehttp/guzzle Version ^7.8.1 | — | — |
laravel/framework Version ^9.46.0|^10.34.2|^11.0 | — | — |
openai-php/client Version ^v0.9.1 | — | — |
lucianotonet/groq-php Version ^0.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.