The license files disagree, and the repository has no security policy or automated security scanning. Tests, a substantial README, and release notes for this version provide useful maintenance and adoption context.
60%
Total Score
50
79
75
The manifest declares GPL-3.0, while the artifact and repository license files are detected as MIT. The release is licensed, but this mismatch creates a meaningful transparency and compatibility concern.
Only one registry maintainer is listed, which increases bus-factor risk for a small package. The repository has a matching owner and recent historical release activity, so this is a moderate rather than severe concern.
The package has 11 releases since August 2023, but none in the last 12 months; the latest release was about 18 months ago. This indicates materially reduced maintenance activity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. No newer activity is provided to offset the maintenance concern.
Composer build tooling is present, but no security-scanning tool was detected. That leaves the project's dependency and code security checks less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.