It has a clear MIT license, tests, a README, and a repository that matches the package. The large dependency set, install-time scripts, and absent security policy add maintenance overhead.
42%
Total Score
33
50
75
50
The package has 42 releases but none in the last 12 months; its latest release was published in October 2017, nearly nine years ago. This strongly indicates abandonment despite the substantial historical release count.
The repository recorded no commits and no active maintainers in the last three months, consistent with the last release and push occurring in October 2017. The repository is not archived, but that does not compensate for the prolonged inactivity.
The release declares 18 runtime dependencies, including the framework and many application modules. This broad dependency surface increases compatibility and maintenance burden for an otherwise inactive package.
The package runs post-autoload-dump, post-install-cmd, and pre-update-cmd scripts. Install-time execution deserves caution because it adds behavior beyond ordinary dependency loading.
The repository is owned by the same individual namespace as the package, providing direct ownership consistency. It is user-owned rather than organization-backed, so there is no broader institutional maintenance signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ~1.0 | — | — |
fideloper/proxy Version ~3.3 | — | — |
laravel/framework Version 5.5.* | — | — |
cartalyst/sentinel Version ~2.0 | — | — |
idavoll/tag-module Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.