It has an MIT license, a usable README, and source that matches the package under organization ownership. Its eight runtime dependencies and lack of security scanning or a security policy add maintenance and oversight burden.
44%
Total Score
50
75
75
The latest release was published in October 2019, with no releases in the last 12 months. This is a substantial abandonment concern for a framework integration package.
The repository recorded zero commits and zero active maintainers during the last 3 months, reinforcing the long release gap and indicating no current maintenance activity.
Composer build tooling is present, but no security scanning tools were detected. That leaves dependency and code-health checks less evident than they would be in a more actively maintained project.
The repository is not archived, which is a meaningful compensating signal, but its last push was in February 2022 and does not offset the prolonged lack of releases and recent commits.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is an oversight gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.7 | — | — |
overtrue/wechat Version ~4.0 | — | — |
ibrand/laravel-active Version ~2.0 | — | — |
prettus/l5-repository Version ^2.1 | — | — |
laravelcollective/html Version ^5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.