Its Apache-2.0 licensing and focused source tree make the package easy to inspect. The missing security policy and minimal project safeguards leave little evidence of ongoing care.
43%
Total Score
25
100
75
75
The package has 11 releases, but its latest release was in February 2021 and it has had no releases in the last 12 months, indicating prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and a substantial abandonment risk.
The package and repository are owned by the same individual account rather than an organization. This is consistent ownership, but it offers no organizational maintenance backing to offset the inactive history.
The repository has zero stars and forks and only two watchers. Popularity is not decisive, but these numbers provide no meaningful supporting evidence of active use or review.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest hygiene gap, not evidence that the package is unsafe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=5.4.0 | — | — |
ianrothmann/laravel-vue-bridge Version * | — | — |
spatie/laravel-translation-loader Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.