Clear documentation, release notes, and organization ownership support adoption. Maintenance has gone quiet, with no releases for about six years and no recent commits; the missing security policy is a smaller transparency gap.
56%
Total Score
50
75
50
The package has 45 releases and a historically regular cadence, but it has made no release in about six years and none in the last 12 months. That materially raises abandonment risk for a dependency.
There were zero commits and zero active maintainers during the last three months. Combined with the old latest release, this is the strongest evidence that ongoing maintenance is limited.
Only one issue and two pull requests remain open, but there were no new or closed issues or pull requests in the last month. This is consistent with a quiet maintenance state.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. That is a modest supply-chain hygiene gap rather than evidence of abandonment by itself.
The linked repository is not archived, which is better than an explicitly retired project. Its last push in 2023 still indicates that the repository has not seen recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^3.0 | — | — |
laravel/framework Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.