Its clear licensing, stable major version, and organization ownership provide useful context. Maintenance has effectively stopped since February 2025, while the library artifact offers no README, security policy, tests, or changelog.
58%
Total Score
75
81
50
The artifact has no README, which makes a library harder to integrate. Missing tests and changelog files are normal for published package artifacts and are not gaps here.
The package has 70 releases and a rapid historical median interval of about 3 days, but it has had no release in roughly 19 months. That long pause lowers confidence in ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the extended release gap. This is a meaningful abandonment concern despite the repository not being archived.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance-hygiene gap, not a severe risk by itself.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters for a library dependency but is partly offset by the package's clear license and organization backing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.8|^3.0 | — | — |
symfony/cache Version ^5.4|^6.0|^7.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0 | — | — |
illuminate/database Version ^v8.83|^9.0|^10.0|^11.0 | — | — |
symfony/http-kernel Version ^5.4|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.