It has a clear README, tests, matching source repository, MIT licensing, and no install-time scripts. Its focused dependency set is reasonable, but the absent security policy limits transparency for a package with no recent project activity.
43%
Total Score
38
100
78
88
The package has had no releases in the past 12 months, and its latest release was nearly 5 years ago. Eight releases show an established history, but the prolonged pause is a strong abandonment concern.
There were no commits or active maintainers in the past 3 months. Combined with the last push nearly 5 years ago, this is strong evidence that maintenance has stopped.
Only one registry account has publish access. That is a thin publishing base for an individually owned project and increases continuity risk if that maintainer becomes unavailable.
The repository is owned by an individual account rather than an organization, so the single registry maintainer is not offset by visible organizational backing.
There were no new or merged pull requests in the past month and no issue activity was recorded. This is consistent with the broader inactivity concern, although the open issue count is unknown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.0 | — | — |
league/flysystem Version ~1.0 | — | — |
owen-it/laravel-auditing Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.