The package has one listed maintainer and five runtime dependencies, leaving little visible support capacity. The registry does not mark it deprecated, but the source repository could not be found, so maintenance and provenance remain difficult to verify.
38%
Total Score
50
50
50
The package has had no release in nearly 10 years, despite 83 releases during its earlier activity. That prolonged silence is strong evidence of abandonment risk.
Five runtime dependencies create meaningful upkeep and compatibility exposure for a package that is no longer releasing. No dependency-specific failure is shown, so this is a secondary concern.
Only one account has publish access, so the package has a thin visible maintenance base. This increases continuity risk, especially alongside the long release gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
czim/laravel-service Version ^0.9 | — | — |
league/oauth2-client Version ^1.0 | — | — |
czim/laravel-dataobject Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.