There is no security policy, and the declared GPL-2.0-or-later license differs from the detected GPL-2.0 text. The repository is organization-backed and not archived, but that does not offset the long release and commit gap.
42%
Total Score
50
50
50
The package has made no release in over six years, despite 20 releases overall; this is strong evidence that the published version is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the prolonged release hiatus and increasing abandonment risk.
The artifact includes a license file, but its detected GPL-2.0 text does not exactly match the declared GPL-2.0-or-later license, creating a licensing clarity concern.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a framework with broad application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 7.0.* | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.