The MIT declaration and Composer setup are clear, while organization ownership adds some continuity. Consumer documentation is absent, and the repository/package naming mismatch warrants checking provenance.
45%
Total Score
67
57
100
The package is about five years old, has six releases, and has had no release in the last 12 months; the latest release was in September 2021. This materially raises abandonment risk.
Only one registry publisher is listed, limiting publishing redundancy. The organization-owned repository provides some backing, so this is a moderate rather than severe concern.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but a missing README is a real consumer-documentation gap for a Laravel package.
The repository recorded zero commits and zero active maintainers in the last three months. Although it is not archived, the absence of recent commit activity weakens confidence in ongoing maintenance.
The repository name does not match the package name, and no README mention was available. This may be a legitimate subpackage or monorepo relationship, but the ownership of this package is not clearly demonstrated.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.