The MIT license, usable README, small dependency set, and matching organization-owned repository support straightforward use. The package has little recent evidence of active maintenance, so pinning this version carries abandonment risk.
58%
Total Score
75
100
88
75
The latest release was November 2, 2021, and there have been no releases in the last 12 months. That long release gap is meaningful abandonment risk for a package developers may need to keep compatible with its ecosystem.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having had no push for more than four years. This materially raises the risk that compatibility or defects will not be addressed.
The repository uses Composer, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The linked repository has no security policy, so there is no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
larabug/larabug Version dev-master | — | — |
guzzlehttp/guzzle Version ~5.3|~6.0|~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.