It has a clear README, MIT licensing, and no install-time scripts. The small repository has no tests or security policy, so future breakage may be harder to catch.
55%
Total Score
50
100
88
75
The package has only one release, published nearly three years ago, with no releases in the last 12 months. That is substantial evidence of limited ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the stale release history and increasing abandonment risk.
Composer is used as the build tool, but no security scanning tools are present. This is a modest transparency and maintenance gap for a dependency project.
The repository has no security policy. For a small package this is a hygiene gap rather than a severe dependency risk, but it reduces transparency about vulnerability handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-sitemap Version ^6.3 | — | — |
spatie/laravel-package-tools Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.