A small user base and no security policy leave little visible support around the package. The README, MIT declaration, and release notes help, but the older dependency set and install hooks add upkeep risk.
35%
Total Score
0
50
75
67
The package has had no releases in about nine years, with zero releases in the last 12 months. This is strong evidence of abandonment for a framework integration package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving current maintenance capacity unproven.
Eleven runtime dependencies, including several Laravel integrations and two related packages from the same publisher, create a substantial compatibility and upkeep surface for an old release.
The package runs post-install and post-update Composer scripts. These can be legitimate setup hooks, but they increase installation complexity and the code that executes during dependency operations.
The repository has only 1 star, 1 fork, and 1 watcher, so there is little visible community adoption or backup if maintenance stops.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.21 | — | — |
ultraware/roles Version ^5.4 | — | — |
jenssegers/agent Version ^2.4 | — | — |
maatwebsite/excel Version ~2.1.0 | — | — |
laracasts/utilities Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.