Unfit to use for a new dependency: the package is marked abandoned and its source repository is archived. Its last release was in December 2020, despite having a clear README, tests in the repository, and a valid MIT license.
15%
Total Score
50
100
63
80
Packagist marks the entire package as abandoned, with no replacement identified. This is a severe adoption risk because future fixes and compatibility support should not be expected.
The package has had no release in nearly six years and none in the last 12 months. Its earlier cadence shows it was once maintained, but the prolonged gap materially raises compatibility and abandonment concerns.
The linked repository is archived and was last pushed in September 2021, confirming that active development has ended. The matching repository and package reference provide transparency, but do not offset the abandonment risk.
The package and repository are owned by the same individual account, so there is no organization backing shown to provide additional continuity. This reinforces the maintenance concern but is not independently severe.
The repository has no security policy. This is a transparency gap, though the archived status and abandonment are substantially more consequential.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3.1|^7.0.1 | — | — |
laravel/framework Version ^6.0|^7.0|^8.0 | — | — |
spatie/array-to-xml Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.