Usable with caveats: it is a stable, licensed library from an organization-backed repository with tests and release notes, but maintenance appears paused. There have been no releases or commits for about 2 years and 6 months, and the repository lacks a security policy.
62%
Total Score
50
100
83
80
There were no commits and no active maintainers in the last 3 months. Combined with the stale latest release, this is the strongest evidence that ongoing maintenance may have stopped.
The package has a substantial history of 67 releases since 2016, but its latest release was about 2 years and 6 months ago and it had no releases in the last 12 months. This materially raises maintenance risk despite the previously regular cadence.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a quiet project, though it does not by itself prove abandonment.
The repository uses Composer build tooling, but no security scanning tools were detected. The established build setup is positive, while the missing security automation is a modest transparency and maintenance gap.
The linked repository is not archived, but its last push was about 2 years and 6 months ago. The unarchived status helps, yet does not offset the clear inactivity shown by the release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravie/codex-common Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.