The repository is small and has no security policy, which limits transparency and review confidence. More importantly, it has had no releases or commits since November 2016, so compatibility and maintenance risk are substantial.
35%
Total Score
0
67
75
The latest release was in November 2016, with no releases in the last 12 months despite the package being over 10 years old. This is strong evidence of abandonment risk for a framework integration.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history and showing no current maintenance capacity.
The artifact contains a license file and the repository also has one, so the release is licensed. However, the manifest declares MIT while the detected license text is Apache-2.0, creating a material licensing ambiguity.
The repository has only 2 stars and no forks, providing little evidence of broad review or community support. Popularity is supporting evidence rather than decisive on its own, so this is a caution.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This adds a transparency gap, especially for a package used in applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 5.2.* | — | — |
limingxinleo/limx-func Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.