The small codebase is documented and has a clear MIT declaration, but it offers little evidence of ongoing care or validation. Its alpha warning and decade-long inactivity make adopting it a liability for current Laravel projects.
34%
Total Score
0
69
75
The latest release was about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package intended to support active Laravel projects.
There were 0 commits and 0 active maintainers in the last 3 months, and the repository was last pushed about 10 years ago. This directly indicates that maintenance has stopped.
The repository has only 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of a maintained user community.
Composer build tooling is present, but no security scanning tooling is reported. The missing scanning is a modest transparency and maintenance gap, especially alongside the long inactivity period.
The repository has no security policy. For a small, inactive command-line project this is not independently severe, but it reduces transparency about how security issues would be handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^3.0 | — | — |
funivan/php-tokenizer Version ^0.1 | — | — |
ignasbernotas/console Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.