The package includes tests, release notes, a clear MIT license, and no install-time scripts. Its small project footprint, absent security policy, and unpinned workflow actions leave less safety margin for a dependency whose last registry release was over a year ago.
62%
Total Score
67
100
83
75
The package has 10 releases since February 2024, but none in the last 12 months and the latest was over a year ago. This materially raises maintenance and abandonment concern.
There were no commits and no active maintainers in the three months measured, which is a concrete sign of slowed maintenance.
There are no open issues or pull requests and no recent issue or pull-request activity. This is neutral rather than strong evidence of health because it may also reflect a small, inactive user base.
The repository has 12 stars and 1 fork, indicating a small adoption footprint. Popularity is supporting evidence only, but this provides little external maintenance signal.
Composer build tooling is present, but no security scanning tools are reported. That leaves a modest transparency and verification gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
laravel/framework Version ^12.0 || ^11.0 || ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.