The package has a useful README and tests, and its MIT licensing and lack of install scripts reduce adoption friction. However, it has not published a release since August 2016 and shows no recent commits, so maintenance risk is substantial.
38%
Total Score
0
69
75
The package has 18 releases but none in the last 12 months; its latest release was in August 2016, roughly 10 years ago. This strongly indicates that the dependency is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed in April 2023, current development activity is absent.
The repository name does not match the package name, which creates some ownership uncertainty, although the README does mention this package and reduces the concern.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest hygiene gap rather than evidence that the release is unsafe.
The linked repository has no security policy. This is a transparency gap for a package that handles application data, though it is secondary to the much stronger maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 5.* | — | — |
webonyx/graphql-php Version ~0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.