The MIT license, matching repository, and clean package contents improve transparency. A single maintainer and no security scanning leave limited support for future fixes.
43%
Total Score
25
50
71
83
Only two releases were published, both in August–September 2022, with no release in roughly four years. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and indicating no visible ongoing maintenance.
The package declares six runtime dependencies and no development dependencies. This is a moderate dependency surface for a common-library package, with no separate test tooling visible.
One registry publishing account provides a thin maintainer base, increasing continuity risk when there is no recent activity. The repository is user-owned rather than organization-backed.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these values provide no additional indication of community support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^3.4.6 | — | — |
illuminate/support Version ^8.83.23 | — | — |
ezyang/htmlpurifier Version ^4.14.0 | — | — |
doctrine/annotations Version ^1.13.3 | — | — |
dflydev/apache-mime-types Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.