The organization-owned repository matches the package and has a clear README, but it lacks a security policy and automated security scanning. The package is licensed and has no install-time scripts.
60%
Total Score
75
86
75
This is the only release, published about 1 year and 9 months ago, with no releases in the last 12 months. That leaves meaningful uncertainty about ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the single old registry release, this suggests maintenance may have gone quiet.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no published security policy. For a Laravel integration package, that weakens the project's documented process for handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/support Version ^6.0 | ^7.0 | ^8.0 | ^9.0 | ^10.0 | ^11.0 | — | — |
joylab/tarjim-php-client Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.