The repository has tests and the package is clearly licensed, but maintenance stopped shortly after its 2016 release. It also lacks security scanning and a security policy, leaving an old Laravel integration with little ongoing oversight.
38%
Total Score
0
100
67
75
The package has had only 3 releases, all in October 2016, with no release in nearly 10 years. That long gap is strong evidence of abandonment for a framework integration.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap and indicating no current maintenance.
Composer is used for the build, but no security scanning tools are present. For an old package with no recent activity, the lack of automated security oversight adds concern.
The repository is not archived, which is a positive counter-signal, but its last push was in February 2017 and does not offset the prolonged inactivity.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is secondary to the much stronger abandonment concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.21 | — | — |
illuminate/support Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.