The GPL-3.0 license is clear, and install-time scripts are absent. The minimal artifact provides little guidance or evidence for validating changes, while the three runtime dependencies increase the cost of taking over maintenance.
35%
Total Score
0
50
71
75
Only two releases were published, both in November 2022, with no releases in the last 12 months. This is strong evidence of an effectively dormant package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The package declares three runtime dependencies and no development dependencies. That is not inherently unsafe, but it increases maintenance and compatibility exposure for a package with no recent activity.
The artifact and repository each contain only LICENSE and composer.json. That very small footprint may fit a personal boilerplate, but it provides little transparency or guidance for adopters.
The published artifact has no README, tests, or changelog; missing tests and changelog are normal for published artifacts, but the absent README leaves consumers without integration guidance. A GitHub release exists for this version, which partly compensates for missing changelog material.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sentry-laravel Version ^3.0 | — | — |
barryvdh/laravel-ide-helper Version ^2.0 | — | — |
krlove/eloquent-model-generator Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.