It has MIT licensing, a substantial README, release notes, and a matching organization-backed repository. The repository has tests and no install-time scripts, but no security policy. Recent repository activity is absent, so maintenance should be verified before adoption.
62%
Total Score
75
89
75
The package has a long history with 129 releases, but its latest registry release was about three years ago and there were no releases in the last 12 months. This is a meaningful maintenance concern despite the mature release record.
There were zero commits and zero active maintainers in the measured three-month period. That is a direct sign of currently absent development activity and raises maintenance risk.
The repository uses Composer build tooling, but no security scanning tool was detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is less serious than abandonment or deprecation evidence.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-32645 hyn/multi-tenant is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 5.6.0 - 5.7.2. | 5.6.0 - 5.7.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.0 | — | — |
doctrine/dbal Version ~2.5|~3.0 | — | — |
laravel/framework Version ^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.