The repository is tiny and lacks security scanning, limiting confidence in future changes. Its MIT license, clear README, and matching source repository improve transparency, but do not offset the long maintenance gap.
38%
Total Score
0
67
75
The package has 38 releases but none in the last 12 months, and its latest release was published in January 2016. This long period without releases is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the last push occurring in November 2016. That leaves little evidence of ongoing maintenance capacity.
The repository has 1 star, 0 forks, and 1 watcher, providing little community visibility or supporting evidence for continued maintenance. Popularity is only supporting evidence, but here it does not offset the inactivity.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are configured. This is a modest transparency and maintenance-hygiene gap.
The repository has no security policy. For a small, inactive package this reduces the clarity of its vulnerability-reporting process, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version 4.2.x|~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.