The repository is small and has no security policy, although the package is licensed, tested, and documented. Pin 1.0.3 only if your application is locked to Lumen 5.
38%
Total Score
57
75
The package has had no release in more than 10 years, with only five releases overall and none in the last 12 months. This is strong evidence of abandonment risk despite the package's early release cadence.
The repository is not archived, but its last push was in August 2016, matching the long release gap and indicating that it is effectively dormant.
The repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but these figures provide no meaningful community support to offset the maintenance concerns.
No security policy was found in the repository. For a framework integration package, this reduces transparency and leaves vulnerability-reporting expectations unclear.
The assessed release is 1.0.3, while the reported latest version is v0.1 and the stable-major indicator is false, suggesting inconsistent or immature version metadata. The release is not marked prerelease, which provides limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zircote/swagger-php Version ~2.0 | — | — |
laravel/lumen-framework Version ~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.