The README, matching source repository, and MIT license make the package straightforward to inspect and integrate. Its small user base and absent security tooling add maintenance uncertainty.
35%
Total Score
50
69
88
The package has only two releases, with the latest published in April 2016 and none in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility or security maintenance.
There were no commits and no active maintainers in the last three months. Combined with the last push in 2017, this indicates that fixes and compatibility updates are unlikely.
The repository has only 3 stars and 1 fork. Popularity is not decisive, but this limited visible adoption provides little supporting evidence for ongoing maintenance.
Composer is used for builds, but no security scanning tools are present. This is a transparency and hygiene gap, though it is less significant than the prolonged inactivity.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was on April 22, 2017 and therefore does not show current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
baum/baum Version ~1.1 | — | — |
vespakoen/menu Version 3.* | — | — |
illuminate/support Version ^5.0 | — | — |
lavary/laravel-menu Version dev-master | — | — |
illuminate/contracts Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.