Usable with caveats: the package is licensed, tested, stable, and backed by a matching repository, but it has had no registry release in about 18 months and shows no commits in the last 3 months. Very low adoption and no documented security policy add modest maintenance and transparency concerns.
68%
Total Score
50
100
83
50
The package has nine releases since February 2020, but none in the last 12 months and the latest release was about 18 months ago. This suggests slowing maintenance, although the repository was pushed more recently.
The repository recorded zero commits and zero active maintainers in the last 3 months. That is a concrete maintenance concern for a dependency, even though the repository is not archived.
The repository has only 2 stars, 0 forks, and 1 watcher. Low adoption is supporting caution rather than a decisive risk because the package is small and other project signals are present.
The repository uses Composer and Make, but no security-scanning tools were detected. This leaves a modest gap in maintenance and supply-chain hygiene.
No security policy was found in the repository. This weakens vulnerability-reporting transparency, but it is not by itself evidence that the package is unsafe to use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.