Its MIT licensing and direct package/repository match improve transparency. A single maintainer and no security policy leave little evidence of ongoing care for future changes.
40%
Total Score
50
69
75
The last release was about 8 years ago, with no releases in the past 12 months; this is strong evidence of abandonment risk despite five releases shortly after the initial launch.
Only one registry account has publish access, and the project is user-owned rather than organization-backed. Combined with the long inactivity period, this indicates limited visible maintenance capacity.
The artifact includes a README, but it is only 13 characters long and the repository has no tests or changelog. Missing tests and changelog are normal for published artifacts, while the extremely minimal README weakens consumer transparency.
The repository has zero stars, forks, and watchers, offering no supporting evidence of adoption or external validation; this is supporting caution rather than a verdict by itself.
The repository is not archived, which is a positive, but it was last pushed about 8 years ago and provides no evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ~5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.