Organization backing, a matching repository, release notes, and a changelog provide useful transparency. The project has no security policy, and recent repository activity is limited despite the repository remaining available.
62%
Total Score
75
86
50
The manifest declares MIT, but the artifact license file was recognized as Apache-2.0. Although a license file is present, the mismatch creates uncertainty about the applicable terms.
The latest registry release was published in February 2023, with no releases in the last 12 months; this indicates stale release maintenance for a package consumers may still depend on.
The repository recorded zero commits and zero active maintainers in the last 3 months, which lowers confidence in ongoing maintenance even though it is not archived.
The linked repository has no security policy, leaving the project's reporting and response process undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0 | — | — |
webonyx/graphql-php Version ~14.11.3 | — | — |
dreamfactory/df-core Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.