The MIT license and small, transparent Composer package are positives. Its maintenance history is too thin for a dependable library, with no tests or security policy to support ongoing care.
38%
Total Score
50
100
72
75
This is the only release, published more than eight years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a library dependency.
The package includes a README, while the absence of tests and a changelog in the published artifact is normal packaging practice. The repository also reports no tests or changelog, leaving little evidence of project verification.
The package and repository are owned by the same individual account, so there is no apparent ownership mismatch. Individual ownership does not provide organizational maintenance capacity.
There are no open issues or pull requests and no activity in the last month. This is consistent with a dormant project, though the signal alone does not prove abandonment.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide no additional confidence in project maturity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^5.5 | — | — |
prettus/l5-repository Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.