The package has only two releases, both from 2022, and no recent commits or active development. It has a clear MIT license and focused dependency, but the small codebase has no tests or security policy.
34%
Total Score
75
100
60
50
The package borrows the identity of the much more established laravel/sail, with borrows_lookalike_identity true. Although artifact overlap is zero, consumers may most likely have intended the lookalike package rather than this differently owned package.
Only two releases exist, with the latest published about four years ago and none in the last 12 months. This is strong evidence of an inactive package rather than an actively maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The linked repository is present and not archived, but that does not offset the lack of recent work.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a hygiene and transparency gap, though it is secondary to the inactivity and identity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.172 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.