45%
Total Score
unhealthy
Risky: maintenance has been inactive for over six years, despite an unarchived, package-matching repository.
The package has 30 releases, but none in the last 12 months; its latest release was over six years ago. The earlier five-to-six-day median interval shows prior activity but does not offset the current halt.
There were no commits and no active maintainers in the last three months, consistent with the repository having stopped receiving changes for over six years. This is strong evidence of limited ongoing maintenance capacity.
Composer build tooling is present, supporting a conventional build, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This matters more for an old dependency with no recent maintenance activity.
The assessed version is still a beta release, although only 5% of recent releases were prereleases. That leaves some maturity uncertainty for a dependency that has not advanced recently.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 5.3|~6.0 | — | — |
illuminate/support Version 5.5.*|5.6.*|5.7.*|5.8.* | — | — |
justinrainbow/json-schema Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.