A single maintainer and no automated security scanning reduce confidence, while the clear README and changelog help consumers. The small dependency surface and matching MIT license are reassuring.
61%
Total Score
50
100
88
50
One registry maintainer creates a thin publishing base and increases continuity risk. The linked repository is owned by the same individual, providing some consistency but not broader maintainer capacity.
The package has had no releases in the last 12 months, and its latest release was about 18 months ago. Its 10 releases since 2020 show some history, but current maintenance appears paused.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the extended release gap. The repository is not archived, which partially offsets the abandonment concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene and assurance gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it is less serious than an archived or deprecated project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.