Its small dependency surface and matching source repository make the package easy to trace. No releases or repository commits have appeared since 2014, and the license files include both MIT and GPL-3.0, so ownership and licensing should be resolved before adoption.
32%
Total Score
25
100
60
75
The package has only 2 releases, with the latest published in August 2014 and none in the last 12 months. This long period without releases is strong evidence of abandonment for a Laravel integration package.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package having been inactive since 2014. No provided maintenance signal compensates for this gap.
The manifest declares MIT and license files are present, but artifact detection also identifies GPL-3.0 alongside MIT. The additional GPL-3.0 material creates licensing ambiguity that should be checked before use.
Only one registry account has publishing access, while the repository owner is a personal account rather than an organization. This is a thin apparent maintainer base, although access records do not prove who actively maintains the code.
The repository uses Composer, but no security scanning tools were detected. This is a modest hygiene gap and does not outweigh the package's maintenance history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 4.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.