Tests and clear setup instructions make the project easier to evaluate, and the source repository matches the package. Its single-user ownership and lack of security tooling add concern, while the install-time scripts deserve extra care.
35%
Total Score
50
100
69
50
The package was last released on August 26, 2015, about 11 years ago, with only four releases and none in the last 12 months. This is strong evidence of abandonment risk.
The package runs several Composer install and update lifecycle scripts, including post-create-project and post-install commands. These increase installation complexity and warrant review, but the signal alone does not show harmful behavior.
Only one registry account has publish access. Because the project is user-owned rather than organization-backed, this provides limited publishing redundancy, although access records do not prove actual maintenance activity.
Composer is used as the build tool, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The linked repository is not archived, which is a positive counterweight to the stale release history. However, its last push was also in August 2015.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
teepluss/theme Version dev-master | — | — |
laravel/framework Version 5.1.* | — | — |
laravelcollective/html Version ^5.1 | — | — |
barryvdh/laravel-debugbar Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.