The package has a coherent source tree, MIT licensing, and no install-time scripts. Its single-person ownership and lack of security scanning leave limited capacity and transparency for future fixes.
38%
Total Score
25
50
58
75
The latest release was about 4 years and 10 months ago, with no releases in the last 12 months and only two releases overall. This is strong evidence of abandonment risk for a Laravel integration package.
There were no commits and no active maintainers in the last three months, while the repository was last pushed about 4 years and 10 months ago. This strongly supports the release-history evidence of abandonment risk.
The package declares four runtime dependencies and no development dependencies. This is a manageable dependency surface, though the lack of development dependencies also provides little evidence of a maintained test setup.
Only one registry maintainer is listed. Because the repository is owned by an individual rather than an organization, this indicates a thin publishing and continuity base.
A README is present, but it is only 48 characters and provides minimal consumer guidance. Missing tests and changelog files are normal for a published artifact and are not treated as gaps here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
illuminate/support Version ^7.0|^8.0 | — | — |
zendframework/zend-diactoros Version ^2.2 | — | — |
symfony/psr-http-message-bridge Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.