The MIT license, README, tests, release notes, security policy, and matching repository provide useful transparency. CI and static analysis exist, but the workflow uses an unpinned container image, increasing maintenance and build-integrity concerns.
46%
Total Score
0
72
75
Only two releases exist, and none were published in the last 12 months; the latest release was about four years ago. This is strong evidence of abandonment risk for a Laravel dependency.
There were no commits and no active maintainers in the last three months. Combined with the long release gap, this materially raises abandonment risk.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of a broad support community.
The repository is not archived, which preserves the possibility of future maintenance, but it was last pushed about four years ago and therefore does not offset the inactivity evidence.
Version 0.0.2 is not a stable major release, so compatibility guarantees are limited. Its non-prerelease status offers only a small counterpoint.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^9.0 | — | — |
parsecsv/php-parsecsv Version ^1.3 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.