Recent maintenance is minimal, with one contributor making one commit in three months. Tests, licensing, and release notes are present, but the single-maintainer base and unpinned workflow actions add uncertainty.
39%
Total Score
50
83
75
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a major adoption concern even though version 3.0.0 was recently released.
One contributor made all commits during the last three months, leaving maintenance dependent on a single active person.
The repository recorded only one commit in the last three months, showing limited recent maintenance despite the latest release being current.
The repository has no security policy, which weakens vulnerability-reporting transparency for a package that processes request IP addresses.
The workflow audit completed cleanly with no dangerous triggers or findings, but both analyzed action references are unpinned, leaving builds exposed to action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.0||^9.0||^10.0||^11.0||^12.0||^13.0 | — | — |
jord-jd/php-geolocation Version ^5.0 | — | — |
jord-jd/do-file-cache-psr-6 Version ^3.0||^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.