It includes an MIT license, tests, a substantial README, and a repository that clearly matches the package. The absence of recent maintenance makes this a legacy dependency; pinning this version requires compatibility testing and ownership of future fixes.
40%
Total Score
75
78
83
The package has had no releases in the last 12 months, and its latest release was published on November 17, 2017. Twelve historical releases show past activity but do not offset nearly nine years without a new release.
The repository has one open issue but no new or closed issues and no pull-request activity in the last month. This provides no evidence of current project upkeep.
Composer is used as the build tool, but no security-scanning tooling is reported. This is a modest transparency gap, though it is less significant than the prolonged inactivity.
The repository is not archived, which preserves a path for maintenance, but it was last pushed on November 17, 2017. This supports the release history's evidence of prolonged inactivity.
The repository has no security policy. That limits guidance for reporting and handling vulnerabilities, adding a small transparency concern to an already inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version ^1.2 | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
guzzlehttp/promises Version ^1.3 | — | — |
laravel/lumen-framework Version 5.3.* | — | — |
lushdigital/microservice-model-utils Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.