The package includes a README, tests, and a source repository that matches its name. Its MIT declaration and lack of install-time scripts help, but the old framework-era dependencies and missing security policy add maintenance risk.
42%
Total Score
25
50
80
75
The latest release was about 7 years ago, with no releases in the last 12 months and only 3 releases overall. This is strong evidence that the published release is outdated, despite its short early release interval.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, while its last push was about 5 years ago. This indicates sustained abandonment risk.
The package declares 12 runtime dependencies, including a Laravel framework integration, authentication, messaging, image, and repository packages. This broad application-style dependency surface increases compatibility and maintenance exposure for an old release.
There were no new or closed issues or pull requests in the last month, and no open work remains. Combined with the absent recent commits, this supports inactivity rather than an actively stable maintenance process.
The linked repository has no security policy. For a package providing administration, authentication, permissions, and API features, that is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jpush/jpush Version ^3.5 | — | — |
laravel/dusk Version ^2.0@dev | — | — |
cebe/markdown Version ^1.1 | — | — |
laravel/tinker Version ~1.0 | — | — |
guzzlehttp/guzzle Version ^6.2@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.