The package includes a clear MIT license, tests, a changelog, and useful README documentation. Maintenance evidence is weak because no commits were recorded in the last three months, despite the repository being pushed more recently.
57%
Total Score
50
83
75
The package has 202 releases and a long history, but its latest registry release was nearly six years ago and there were no releases in the last 12 months. That materially raises compatibility and abandonment concerns.
No commits and no active maintainers were recorded in the last three months. The 2025 push is compensating evidence that prevents this from indicating clear abandonment, but current maintenance remains uncertain.
The repository has no stars and only one fork, offering little community evidence. Popularity is supporting evidence only, so this modestly limits confidence rather than determining the verdict.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository has no security policy, leaving vulnerability reporting expectations unclear. This lowers project transparency but does not by itself make the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version >=2.3 | — | — |
erusev/parsedown Version 1.* | — | — |
laravel/framework Version >=5.5 | — | — |
kodicms/laravel-assets Version 0.* | — | — |
kodicomponents/support Version 0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.