The repository has only one commit from one contributor in the last three months and no security scanning or security policy. It is licensed, documented, not archived, and has a matching repository, but the release record shows no releases in over five years.
58%
Total Score
50
88
75
The repository is owned by a user account rather than an organization, so there is no provided evidence of broader project backing to offset the single-contributor activity.
The registry shows 206 releases but none in the last 12 months, with the latest release dated November 2020; this indicates a long release gap for a dependency release.
All recent commit activity comes from one contributor, leaving maintenance dependent on a single observed individual; the repository owner is a user account rather than an organization.
Only one commit was recorded in the last three months, so observed maintenance activity is very limited even though the repository was recently pushed.
Composer build tooling is present, but no security-scanning tooling was detected, leaving an avoidable security-maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^4.2|^5.0 | — | — |
league/flysystem Version ^1.0.49 | — | — |
spatie/db-dumper Version ^2.12 | — | — |
illuminate/events Version ^5.8.15|^6.0|^7.0|^8.0 | — | — |
illuminate/console Version ^5.8.15|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.