Tests, release notes, and a recent push provide useful maintenance evidence. The registry status still makes long-term dependency planning risky, while one-person activity and unpinned workflow actions add smaller concerns.
38%
Total Score
50
100
81
83
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a substantial adoption and continuity risk despite the recent release activity.
The repository is owned by an individual rather than an organization, so there is no visible organizational maintenance buffer to offset the concentrated contributor activity.
One contributor made all commits in the last 3 months. Because the repository owner is an individual, this leaves maintenance dependent on a single active person.
Only 1 commit was recorded in the last 3 months, showing some activity but a limited recent maintenance pace.
The project uses Composer build tooling, but no security scanning tools were detected. This is a minor assurance gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^5.1||^6.0||^7.0||^8.0||^9.0||^10.0||^11.0||^12.0||^13.0 | — | — |
php-school/cli-menu Version ^3.0 | — | — |
jord-jd/json-key-value-store Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.