The package has strong documentation, tests in the repository, a changelog, and clear licensing. Its release burst ended after five releases, and the workflow audit found a high-confidence automation issue.
15%
Total Score
100
63
Packagist marks the entire package as abandoned and names foxws/laravel-ab-av1 as its replacement. This is a direct warning against taking a new dependency on this package.
The linked repository is archived, so it is no longer an active place for maintenance or fixes. Its last push was in January 2026, reinforcing the abandonment concern.
All five releases occurred within roughly one week, with no release activity afterward despite the package being about eight months old. This suggests a short-lived project rather than an established maintenance cadence.
Version 0.5.0 is not a stable-major release, so the API may still change. That concern is secondary to the package-level abandonment signals.
All five workflows were analyzed, but every action reference is unpinned and a high-confidence bot-conditions finding may allow actor context to be spoofed. The audit also reports write permissions in three workflows, adding workflow hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
illuminate/process Version ^11.0 || ^12.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 | — | — |
illuminate/filesystem Version ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.