The source repository is intact and includes tests, a changelog, and release notes. However, commit and issue activity has stopped, security guidance is absent, and one person remains the sole registry maintainer.
42%
Total Score
38
50
81
50
The latest registry release was over 5 years ago, with no releases in the last 12 months. This is a substantial abandonment risk despite 48 releases showing earlier development activity.
The repository had zero commits and zero active maintainers in the last 3 months. Combined with the old registry release, this materially raises the risk that fixes and compatibility updates will not arrive.
The package declares 21 runtime dependencies for a full Laravel application, creating meaningful dependency maintenance exposure. The profile is substantial but consistent with the application's broad feature set.
Only one account has registry publish access. That is a thin publishing base for a user-owned project and increases continuity risk when combined with the lack of recent activity.
The package and repository are owned by the same individual account, with no organization backing shown. This is consistent ownership but provides limited evidence of institutional maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mews/captcha Version ^3.2 | — | — |
doctrine/dbal Version ^2.10 | — | — |
laravel/scout Version ^7.2 | — | — |
predis/predis Version ^1.1 | — | — |
laravel/tinker Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.