The project has had no commits for over two years and no recent releases, while its repository lacks a security policy. It does have a clear MIT license, release notes, and organization backing.
43%
Total Score
50
75
50
The package borrows the identity of the much more established laravel/legacy-factories, with 895,786 monthly downloads versus 6 and borrows_lookalike_identity=true. This is strong evidence that consumers may select it while intending the other package.
Only four releases have appeared since May 2022, with no releases in the last two years and a median interval of about 305 days. That indicates a very slow maintenance cadence for a package last released in June 2024.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the long release gap, this raises abandonment risk.
The repository has no security policy. For a Laravel connector handling license validation, this reduces transparency about how vulnerabilities should be reported and managed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0 || ^10.0 || ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.