The package includes tests, documentation, and release notes, but its single maintainer and inactive recent commits reduce confidence in ongoing support. Workflow dependencies are also unpinned, increasing maintenance and build-integrity risk.
42%
Total Score
50
100
81
50
The package borrows the identity of laravel/pao, which has 4,798,062 monthly downloads versus 198 here, and explicitly lacks fork or integration signals. That makes consumer confusion likely and is a severe supply-chain concern.
Only one registry publishing maintainer is listed, and project_backing identifies the repository owner as an individual rather than an organization. This creates a thin support and bus-factor profile.
The package has five releases since March 2024, but none in the last 12 months; its latest release was August 2024. This long release gap raises abandonment risk despite the stable version.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed recently according to repository metadata, there is no observed recent development activity to support ongoing maintenance.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
devizzent/cebe-php-openapi Version 1.6.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.