The package has a clear license, tests, README, matching repository, and no install-time scripts. Maintenance has stopped, with no commits or releases in the last 12 months, while the single maintainer and absent security policy add modest risk.
58%
Total Score
50
100
83
67
Only one account can publish the package, leaving limited publishing redundancy. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of broader maintainer capacity.
The package has 20 releases, but none in the last 12 months; the latest release was about one year ago. This indicates paused maintenance for a dependency that may need compatibility updates.
The repository had zero commits and zero active maintainers in the last three months, consistent with the year-long release gap and indicating paused development.
There were no new issues or pull requests in the last month and no merged pull requests. This provides no recent evidence of active support, although the issue count itself is unknown.
The repository has no stars and two forks. Low popularity is supporting context rather than a verdict, but it provides little evidence of a broad support community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.3.2 | — | — |
illuminate/contracts Version ^5.1||^6.0||^7.0||^8.0||^9.0||^10.0||^11.0|^12.0 | — | — |
magentron/password_exposed Version ^3.2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.