Dragonflies fly on the water, Socialize with fans!
38%
Total Score
unhealthy
Risky: the package appears abandoned and its linked repository does not identify or mention this package.
The package has 14 releases over about 10 years, but its latest registry release was about 7 years ago and it had no releases in the last 12 months. That strongly indicates the published dependency is stale.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with no registry releases for about 7 years, this is strong evidence of maintenance risk.
The linked repository is named fans rather than medz/phpwind and its README does not mention the package. That raises a material concern that the repository may not actually be the package's source.
The package declares eight runtime dependencies, including a framework, search client, SMS provider, and JWT authentication package. This is a substantial dependency surface for an application and increases maintenance exposure, but it is not unusually large on its own.
The manifest declares Apache-2.0, while the repository license file is detected as MIT. That mismatch creates licensing uncertainty even though both sources indicate that licensing information exists.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^6.1 | — | — |
laravel/tinker Version ^1.0 | — | — |
tymon/jwt-auth Version ^1.0.0-rc.3 | — | — |
fideloper/proxy Version ^4.0 | — | — |
laravel/framework Version 5.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.