The stable major version, MIT license, and matching organization repository provide clear provenance. No install scripts or workflow risks are visible, but the limited documentation and security tooling reduce transparency.
42%
Total Score
50
67
100
Only two releases exist, and the latest was published nearly five years ago with no releases in the past year. This strongly suggests abandonment risk despite the package not being deprecated.
The repository recorded no commits and no active maintainers in the past three months, consistent with the nearly five-year gap since its last push. There is no provided evidence of ongoing maintenance.
The package and repository lack a README, tests, and changelog, although release notes exist for this version and the source tree is small. The missing consumer documentation is a real transparency gap for a library.
Composer is used as the build tool, but no security scanning tools are present. This is a modest transparency and maintenance concern rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lumphp/laravel-support Version ^8.0 | — | — |
lumphp/laravel-pipeline Version ^8.0 | — | — |
lumphp/laravel-contracts Version ^8.0 | — | — |
lumphp/laravel-collections Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.