Its MIT licensing, matching repository, and small dependency set make its provenance straightforward. No security policy or scanning tooling is visible, limiting confidence in ongoing maintenance and response capacity.
38%
Total Score
100
57
75
The package has only one release, published about 10 years ago, with no releases in the last 12 months. That long-standing lack of release activity is strong evidence of abandonment risk.
The repository has 1 star, 0 forks, and 1 watcher. Low adoption is supporting evidence of limited project maturity, though popularity alone does not determine health.
Composer build tooling is present, but no security-scanning tooling is reported. That leaves limited evidence of automated security hygiene.
The repository is not archived, which avoids an explicit abandonment marker, but it was last pushed about 10 years ago and provides no evidence of recent maintenance.
The repository has no security policy. This is a transparency and incident-response gap, although it is secondary to the much stronger evidence of stale maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^5.3|^6.0 | — | — |
illuminate/support Version 5.1.*|5.2.* | — | — |
illuminate/contracts Version 5.1.*|5.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.