The MIT license, organization backing, and small dependency surface are reassuring. Missing consumer documentation and absent security tooling leave transparency and maintenance support thin.
42%
Total Score
50
100
75
75
This is the only release, published about 5 years and 7 months ago, with no releases in the last 12 months. That strongly raises abandonment risk, despite the stable 1.0.0 version.
The repository has recorded no commits and no active maintainers in the last 3 months, consistent with the long release pause. No newer activity is provided to offset that concern.
The package has no README, which matters for a library consumers must integrate; the absence of tests and a changelog is normal for published artifacts and is not penalized here.
Composer build tooling is present, but no security scanning tools are configured. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a secondary governance gap alongside the stronger inactivity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^7.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.