It includes a README, tests, and a stable release format, but offers no security policy or scanning. Its repository name matches, though the README does not identify the package.
12%
Total Score
25
50
57
50
Packagist marks the entire package as abandoned, with no replacement provided. That is a severe warning against taking a new dependency on this release.
The latest release was published over 10 years ago, and there were no releases in the last 12 months. This strongly indicates the package is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long-standing lack of maintenance activity.
The package declares five runtime dependencies, including Laravel and JWT components. This is a moderate dependency surface rather than an unusually broad one, though the package's age makes compatibility a concern.
The repository is owned by an organization named InactiveProjects, which is consistent with the observed absence of current development and provides no visible compensating backing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^3.0 | — | — |
laravel/framework Version 5.1.* | — | — |
neomerx/limoncello Version ^0.5.0 | — | — |
neomerx/cors-illuminate Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.