Usable with caveats: the package is licensed, documented, tested, non-deprecated, and backed by a matching repository with a stable release. Maintenance is currently quiet, with no release in over a year and no commits in the last three months; security-policy and workflow permission hygiene are also limited.
68%
Total Score
67
100
88
80
One registry publishing account is listed, which is a limited administrative base; the organization-backed repository provides some compensation, but it does not establish active maintenance.
The project has 11 releases since April 2019, but it has made no release in the last year; this lowers confidence in ongoing maintenance without indicating abandonment by itself.
There were no commits and no active maintainers in the last three months, indicating currently quiet development. The recent registry release and non-archived repository partly offset this, but the inactivity remains a maintenance concern.
Composer build tooling is present, but no security scanning tools were detected; this is a transparency and process gap rather than evidence that the package is unsafe.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.