The MIT declaration, matching repository, and ordinary Composer dependency setup make the package easy to identify and install. Its README is only 21 characters, with no tests or security policy.
38%
Total Score
0
100
71
50
The package has had only two releases, with the latest published in December 2018 and no releases in the last 12 months. This is strong evidence of abandonment for a framework dependency.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and leaving no visible maintenance capacity.
The artifact includes a README, but it is only 21 characters and provides no meaningful consumer guidance. The absence of tests and a changelog is normal for published package contents and is not itself a gap.
Composer is used for the build, which is appropriate for a Packagist package, but no security scanning tools were detected. That weakens maintenance transparency for a framework with several runtime dependencies.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, though it is secondary to the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version 3.2.5 | — | — |
predis/predis Version 1.1.1 | — | — |
symfony/console Version 3.4.18 | — | — |
psr/http-message Version 1.0.1 | — | — |
illuminate/database Version 5.5.44 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.