The repository is small, has one active contributor, no security policy, and uses two unpinned workflow actions. Recent releases, tests, release notes, and a clear license provide useful maintenance evidence, but do not offset the registry abandonment status.
42%
Total Score
50
100
86
67
Packagist marks the entire package as abandoned and names the same package as its replacement, which is a strong warning for future maintenance and dependency safety.
One contributor made all recent commits, leaving maintenance concentrated in a single person with no organizational backing shown.
Only one commit was recorded in the last three months, showing limited recent activity even though it is not absent.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The workflow audit completed cleanly with no dangerous triggers or audit findings, but both analyzed actions are unpinned, reducing build reproducibility and supply-chain assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.