The README, license, and package-to-repository match make its purpose and source easy to check. A single-person project with no security policy leaves less maintenance and response capacity if problems arise.
55%
Total Score
50
81
50
One registry maintainer provides a thin publishing base. The linked repository is owned by the same individual, so this is a capacity concern rather than evidence of mismatched ownership.
The package has had only two releases, with the latest published nearly two years ago and none in the last 12 months. This indicates limited ongoing maintenance, though it does not prove the package is abandoned.
There were no commits or active maintainers in the three months measured, consistent with the nearly two-year release gap. This materially raises abandonment risk.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency and maintenance gap for a package that handles application email templates.
The repository has no security policy, leaving no stated channel or process for reporting vulnerabilities. This lowers response transparency but is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^7.0|^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.