The package is licensed, documented, tested, and has no install-time scripts. Its single-person maintenance base and unpinned workflow actions leave less resilience than a mature dependency.
70%
Total Score
50
100
94
83
The repository is owned by an individual user rather than an organization, so there is no shown organizational handoff capacity to offset the concentrated maintainer base.
All recent commits come from one contributor, so maintenance depends entirely on a single person; the repository owner is a user rather than an organization.
One commit and one active maintainer were observed in the last three months. That is evidence of recent maintenance but represents limited ongoing activity.
Composer is used for builds, but no security scanning tool was detected, leaving a modest process gap for a dependency published to other projects.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^5.1||^6.0||^7.0||^8.0||^9.0||^10.0||^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.