The package includes a substantial README, tests, an MIT license, and a repository that matches the package. Its install-time script, unpinned workflow actions, and absent security policy add maintenance and build-hygiene concerns.
58%
Total Score
25
50
88
50
The repository had zero commits and zero active maintainers in the last 3 months. Combined with the one-release history, this is the strongest abandonment concern in the assessment.
Five runtime dependencies, including Laravel components and other related PHP libraries, create a meaningful dependency surface. The profile is not unusually large for this library, so it is a moderate rather than severe concern.
The package runs a post-autoload-dump install-time script. This adds installation complexity and requires extra trust in package behavior, though it is not by itself evidence of an unsafe release.
The registry namespace and repository owner match an individual account, so the single registry maintainer is consistent with the project's ownership context. This indicates limited apparent organizational backing but is not a problem by itself.
This is the sole release, published 2 years and 5 months ago, with no releases in the last 12 months. That limited history and age reduce confidence in ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kornrunner/keccak Version ^1.1 | — | — |
illuminate/support Version ^8.0|^9.0|^10.9|^11 | — | — |
kornrunner/solidity Version ^0.2.0 | — | — |
illuminate/collections Version ^8.0|^9.0|^10.9|^11 | — | — |
ironchoi/simple-web3-php Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.