The package has clear documentation, an MIT license, repository tests, and a changelog. Its seven runtime dependencies increase upgrade coupling, while the small user-owned project has limited visible activity.
57%
Total Score
50
50
94
83
Seven runtime dependencies, including Laravel and several supporting libraries, create meaningful upgrade coupling for a small support package. This is a maintenance consideration rather than a severe dependency risk on its own.
The source repository is owned by a user account rather than an organization, so the visible maintainer backing is limited. This reinforces the maintenance concern but does not establish abandonment by itself.
The package has 75 releases but all observed releases are concentrated on 14 March 2025, with no releases in the last 12 months. This suggests an inactive release process despite the large historical count.
The repository recorded zero commits and zero active maintainers in the last 3 months. Together with the absent recent releases, this is evidence of slowing maintenance.
The repository has no security policy. This is a transparency gap, although it is less significant for a small support library than for a security-sensitive package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vinkla/hashids Version ^13.0.0 | — | — |
laravel/framework Version ^12.0.0 | — | — |
watson/validating Version ^8.3.0 | — | — |
spatie/laravel-sluggable Version ^3.7.0 | — | — |
spatie/laravel-translatable Version ^6.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.