Usable with caveats: the package is small, licensed, tested, and clearly backed by its matching repository. However, it has had no release or commit activity for about three years and has only one maintainer, so ongoing compatibility support is uncertain.
58%
Total Score
67
100
81
83
Registry publishing access is held by one maintainer. This is a limited administrative base, and the available repository activity does not show a broader active maintenance group.
Only two releases were published, both in May 2023, with no releases in roughly three years. The exact version has release notes, but the long period without updates lowers confidence in continued maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, following its last push about three years ago. For a library dependency, this is a meaningful abandonment risk even though it is not archived.
The repository has zero stars and forks and only one watcher, providing little external evidence of review or adoption. Popularity is supporting evidence rather than a requirement, so this is a caution rather than a severe risk.
Composer is used for the project, but no security scanning tools are configured. This is a modest transparency gap for a small package, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.