The package includes a README and tests, with no install-time scripts or registry deprecation. Its single release and inactive repository leave substantial maintenance and compatibility risk; pinning 1.0.0 is prudent.
40%
Total Score
25
75
88
Only one release exists, published about 8 years ago, with no releases in the last 12 months; this is strong evidence of an unmaintained package.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and increasing abandonment risk.
Only one registry publisher is listed, which limits apparent publishing redundancy; the linked repository is also owned by an individual, so there is no organizational backing to compensate.
The repository has 1 star, 0 forks, and 0 watchers, indicating little external adoption or review; this is supporting caution rather than a verdict by itself.
Composer is used for the build, but no security scanning tool is present; this is a hygiene gap, though the long inactivity is the larger concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ~2.0 | — | — |
laravel/laravel Version >= 5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.