A security policy is missing, while the project has a clear license and a repository that matches the package. The recent release is encouraging, but limited ongoing activity leaves maintenance capacity uncertain.
67%
Total Score
67
94
83
The package is mature at over eight years old with 31 releases, but only one release arrived in the last 12 months. The recent release partly offsets the slower cadence, so this is a maintenance caution rather than abandonment.
The repository recorded zero commits and zero active maintainers over the last three months. The recent release compensates partly, but the lack of current development lowers confidence in ongoing maintenance.
There are six open pull requests but no issues or pull requests were merged in the last month. This suggests some unresolved maintenance backlog, though it is not conclusive evidence of abandonment.
The repository has no documented security policy. For a Laravel CMS package handling authentication, uploads, and application data, that is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.8 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
intervention/image Version ^2.7 | — | — |
pragmarx/google2fa Version ^8.0 | — | — |
bacon/bacon-qr-code Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.