The package has a clear README, MIT licensing, and a repository that matches the package. Its single maintainer, absent security tooling, and roughly 14 months without a new release make long-term support uncertain.
58%
Total Score
50
100
86
75
Only one registry publisher account is listed, which leaves limited visible publishing redundancy for a user-owned project. This is a support-capacity concern rather than evidence of unsafe code.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. Combined with the single maintainer, this provides limited visible project backing.
The package has had four releases, but none in the last 12 months and the latest activity was about 14 months ago. This is a meaningful maintenance concern for a relatively young package.
Composer is used as the build tool, but no security scanning tools are present. This is a modest transparency and hygiene gap, not a severe risk by itself.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a package that handles request and model activity logs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0 || ^11.0 || ^12.0 | — | — |
spatie/laravel-http-logger Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.