The package includes tests, release notes, a clear license, and an identified organization-backed repository. Its framework dependencies and build scripts are also dated, increasing compatibility and maintenance risk for a new project.
36%
Total Score
67
78
50
The latest release was published in June 2015, and there have been no releases in about 11 years. That long release gap is strong evidence of abandonment despite the package having 18 historical releases.
The repository had zero commits and zero active maintainers in the last three months, consistent with roughly 11 years since the latest registry release. This materially raises abandonment risk.
The package runs post-create, post-install, and post-update Composer scripts. These are relevant to a Laravel project template, but they add install-time behavior that should be checked before adoption.
The repository has zero stars and forks and only three watchers. Popularity is supporting evidence rather than a verdict, but these very low counters provide no meaningful adoption signal to offset the inactivity.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are reported. The missing scanning is a hygiene gap rather than proof of an unsafe release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version ~1.0 | — | — |
nukacode/core Version ~2.0 | — | — |
nukacode/menu Version ~0.2 | — | — |
illuminate/html Version 5.0.* | — | — |
laravel/framework Version 5.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.