The package has a clear license, tests, documentation, and a matching source repository. Its install scripts and old Laravel-era implementation add friction, while the project shows no sign of ongoing support.
38%
Total Score
67
50
The package has only 2 releases, both from November 2016, with no releases in the last 12 months and an almost ten-year-old latest release. This is strong evidence of abandonment risk.
The package defines four install-time and update-time lifecycle scripts, which add execution and maintenance complexity during Composer operations. No provided signal shows these scripts are unsafe, so this is a moderate hygiene concern rather than a severe risk.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these counts provide no meaningful external adoption signal to offset the stale project history.
The repository is not archived, but its last push was on November 26, 2016, matching the stale registry history. The unarchived status provides little compensation for the lack of recent activity.
The repository has no security policy. This is a transparency gap for a Laravel backend that handles authentication, roles, settings, and auditing, although it does not by itself establish a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/fractal Version ^0.14.0 | — | — |
yangyifan/upload Version dev-master | — | — |
laravel/framework Version 5.3.* | — | — |
prettus/l5-repository Version ^2.6 | — | — |
owen-it/laravel-auditing Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.