Clear documentation, tests, and matching repository improve confidence, while the MIT license keeps reuse straightforward. The project is not deprecated or archived, but its current maintenance picture is too weak for a new dependency.
36%
Total Score
50
86
50
The latest release was about 5 years and 10 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite 51 historical releases.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long release gap and leaving little evidence of ongoing maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but combined with absent recent activity it provides no external sign of active use or review.
The linked repository has no security policy, so users have no documented security-reporting process to rely on. This is a transparency gap for an admin package.
All 5 workflows were analyzed successfully with no dangerous audit findings, but 11 of 12 action references are unpinned. That weakens build reproducibility even though no high-confidence exploit pattern was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version >=1.0 | — | — |
doctrine/dbal Version ^2.5 | — | — |
league/flysystem Version ~1.1|~2.0 | — | — |
illuminate/support Version ~6.0|~7.0|~8.0 | — | — |
intervention/image Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.