The package is clearly documented, licensed, tested in its repository, and has a small runtime dependency set. Its maintenance signals are outweighed by the repository being archived and the registry marking the package abandoned; use NativePHP/desktop instead.
12%
Total Score
75
100
69
75
Packagist marks the entire package abandoned and names NativePHP/desktop as its replacement, making continued dependency adoption a severe lifecycle risk.
The linked NativePHP organization repository is archived, which strongly indicates the source is no longer intended for active maintenance despite a recent push timestamp.
Although the package has 30 releases over about three years, it has had no releases in the last 12 months, indicating that release activity has stopped.
The repository recorded zero commits and zero active maintainers over the last three months, reinforcing the abandonment concern.
All five workflows were analyzed, but every one of 13 action references is unpinned and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; these add supply-chain hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^6.2|^7.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.