Risky to adopt without taking on maintenance risk. The package has had no release or commit activity since 2019, with only two releases and no tests or security policy; its MIT license, simple dependency profile, and organization-backed repository provide limited reassurance.
42%
Total Score
50
100
61
80
The package is about 7 years old, has only 2 releases, and has had no releases in the last 12 months. This indicates very limited ongoing maintenance for a dependency that may need compatibility updates.
The repository has recorded 0 commits and 0 active maintainers in the last 3 months. Given the last push was in 2019, this is strong evidence that maintenance has stopped or effectively collapsed.
The linked repository is not archived, but its last push was in May 2019. The active archive status is outweighed by the long period without updates when combined with the release_history and repo_commit_activity findings.
The package and repository contain only 6 files, including a provider and service implementation, README, and license. This is not inherently unsafe for a small Laravel integration, but it offers little visible project structure for validation.
A README is present, but it contains only 21 characters and gives little practical guidance. The absence of tests and a changelog is normal for a published artifact, while the repository also provides no tests or changelog to compensate.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.