The release has a clear README, tests in the repository, release notes, and a matching source project. Its long inactivity, absent security policy, and unpinned workflow actions add maintenance and build-transparency concerns.
12%
Total Score
0
40
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because future fixes and support are not indicated.
The package has had no release in about three years and no releases in the last 12 months. Its four-release history shows a stable version, but not ongoing maintenance.
There were no commits and no active maintainers in the last three months, consistent with the archived repository and abandoned registry status.
The linked repository is archived and was last pushed about three years ago. An archived source project is strong evidence that active maintenance has ended.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This matters more for a dependency that is already inactive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^9.0|^10.0 | — | — |
darkaonline/l5-swagger Version ^8.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.