Clear documentation, repository tests, and release notes make integration easier. Workflow package installation and the missing security policy leave modest transparency and build-hygiene concerns.
68%
Total Score
50
88
50
Only one account has registry publishing access, which creates a thin publishing base; the linked repository and matching owner provide some direct project backing but do not remove the continuity concern.
The package has existed since January 2021 and received a release about four months ago, but only one release appeared in the last 12 months, indicating a slower recent cadence rather than abandonment.
The repository recorded no commits and no active maintainers in the last three months, a meaningful sign of recently paused development despite the May release and push.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest gap in ongoing repository hygiene.
The repository has no security policy, reducing transparency about how vulnerability reports are handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0|^7.0 | — | — |
laravel/framework Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.