The package has an MIT license, a README, a security policy, and no install-time scripts. Its repository matches the package and the dependency list is small, but the project shows little adoption and lacks security scanning or pinned workflow actions.
42%
Total Score
50
100
81
83
This is the package's only release, published over six years ago, with no releases in the last 12 months. That leaves maintenance and compatibility largely unverified.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has not received recent maintenance.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these values provide little evidence of active community use or review.
Composer is used for builds, but no security scanning tools were detected. For an old package with no recent maintenance, this is a meaningful transparency and upkeep gap.
Both analyzed workflows use unpinned actions (2 of 2), which weakens build reproducibility. The audit found no dangerous triggers, sinks, or high-confidence findings, so this remains a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^5.5|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.