Apache-2.0 licensing and repository tests improve transparency, but 62 runtime dependencies increase maintenance demands. The absent security policy and very small project footprint provide little visible support for future fixes.
35%
Total Score
25
50
71
50
The package has had no release in more than eight years: its latest release was May 29, 2018, with four releases total and none in the last 12 months. This is strong evidence of abandonment for a framework dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push in May 2018. The prolonged absence of source activity materially increases abandonment risk.
The package declares 62 runtime dependencies, including a broad Laravel and Symfony stack. That creates substantial compatibility and maintenance exposure for a release that has not been updated for years.
There has been no issue or pull-request activity in the last month, while one pull request remains open. This offers no evidence of current maintenance or responsive project support.
The repository has zero stars, one fork, and one watcher. Popularity is not decisive, but this very small footprint provides little supporting evidence of active community adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ~2.0 | — | — |
namshi/jose Version ^7.0 | — | — |
ramsey/uuid Version ~3.0 | — | — |
symfony/yaml Version ~3.3 | — | — |
nesbot/carbon Version ~1.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.