A clear README, tests, and a matching repository make adoption easier, while the small dependency set limits complexity. The project has had no releases or commits for over 20 months, and workflow references are all unpinned.
57%
Total Score
25
100
78
67
There were zero commits and zero active maintainers in the last three months, consistent with the broader absence of releases and raising abandonment concerns.
The package and repository are owned by an individual rather than an organization, so the single-person maintenance model offers limited backing if the maintainer stops work.
The package is about 20 months old but has had four releases concentrated on its first day and none in the last 12 months, indicating no recent release maintenance.
Two stars, no forks, and one watcher indicate a very small user and contributor footprint. This is supporting caution rather than a verdict by itself.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
laravel/framework Version ^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.