The package is clearly identified and easy to inspect, with an MIT license, repository tests, and no install-time scripts. Its very small user base and lack of a security policy provide little evidence of ongoing support.
43%
Total Score
75
67
75
The last registry release was in March 2019, with no releases in the following seven years and only four releases overall. This is strong evidence of stalled maintenance for a package intended to integrate with Laravel.
The repository has no open issues or pull requests and recorded no issue or pull-request activity in the last month. Combined with the old release history, this offers no sign of active upkeep.
The repository has only 2 stars and no forks, indicating very limited adoption and a small external validation base. Popularity is supporting evidence rather than decisive, but it does not compensate for the long maintenance gap.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tools are present. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The linked repository has no security policy. For a package that runs project tooling, this weakens vulnerability-reporting transparency, although it is not evidence of a vulnerability by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 5.5 - 5.8 | — | — |
squizlabs/php_codesniffer Version 3.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.