The MIT license, matching repository, and usable README improve transparency for consumers. The single-maintainer project has little security process and limited community backing, so future fixes may depend on one person.
42%
Total Score
25
100
81
75
The latest release was in January 2020, with no releases in the last 12 months. That long release gap is a substantial maintenance concern for a library dependency.
There were no commits or active maintainers in the last three months, consistent with a project that has not seen recent development and raising abandonment risk.
Only one registry maintainer is listed. The matching user-owned repository provides some ownership clarity, but the narrow maintainer base increases continuity risk.
The repository has only 5 stars and 4 forks, indicating limited community backing. Popularity is supporting evidence rather than a verdict, but it provides little resilience if maintenance stops.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in this network-facing JSON-RPC wrapper.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.3 | — | — |
illuminate/support Version 5.0.*|5.1.*|5.2.*|5.3.*|5.4.*|5.5.*|5.6.*|5.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.