The repository is tiny, with one runtime dependency and no security policy or automated security scanning. It remains licensed, documented, unretracted, and correctly linked to its source, but maintenance has been inactive for over a year.
62%
Total Score
50
100
88
88
The package and repository are owned by the same individual account. That is coherent ownership, but it provides less organizational maintenance capacity than a backed project.
Only four releases have been published since December 2020, with no release in the past year and a median interval of about 413 days. This indicates a slow maintenance cadence, though the package may be deliberately stable.
There were no commits and no active maintainers in the past three months, consistent with the absent releases in the past year and raising abandonment risk.
Composer is used for builds, but no security-scanning tooling is present. That is a modest transparency and assurance gap for a package that handles sensitive request data.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-ignition Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.