The project has no security scanning and relies on one registry maintainer, limiting confidence in ongoing support. Tests, a clear README, matching repository, and MIT licensing provide useful transparency.
38%
Total Score
25
100
79
83
The package has had no registry release in about 6 years and 8 months, with all four releases clustered on January 28, 2020. That strongly suggests abandonment for a dependency assessed at v1.1.1.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and providing no evidence of current maintenance.
One registry maintainer is a thin publishing base, although the linked repository is owned by the same individual, so this is a capacity concern rather than evidence of an ownership mismatch.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful transparency and maintenance gap for a package with no recent activity.
The repository has no security policy, reducing clarity about vulnerability reporting and response. This compounds the absence of recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/lumen-framework Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.