Unfit to use: the source repository is archived and has had no commits for over two years. The package has good documentation, tests in the repository, a license, and matching source, but those positives do not offset clear abandonment risk.
18%
Total Score
50
100
71
50
The package is about 815 days old but has only four releases, all concentrated within roughly one hour, with no releases in the last 12 months. This indicates a release history that stopped shortly after publication.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived status and providing no evidence of current maintenance.
The linked repository is archived, with its last push on July 15, 2024, so ongoing maintenance and fixes cannot be relied on. This is a severe abandonment risk despite the package having a matching repository.
One of three workflows uses pull_request_target, which warrants care because that trigger can run with elevated repository context. No untrusted checkout or script-injection patterns were detected, limiting the concern.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a secondary concern compared with the repository being archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version ^0.1.24 | — | — |
nette/php-generator Version ^4.1 | — | — |
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.