The MIT license, stable version, and absence of install scripts make the package straightforward to evaluate and install. Its release and repository activity stopped in 2017, while the repository has no security policy and the package has no README for consumers.
35%
Total Score
63
75
This is the package's only release, published about 8 years and 9 months ago, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
The artifact has no README, which makes a library harder for consumers to integrate. The missing tests and changelog are normal for a published package, while the GitHub release for this version provides some release documentation evidence.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of a broad user or contributor base.
Composer is used for the build, but no security-scanning tooling is reported. This is a modest supply-chain hygiene gap, not evidence that the release is unsafe by itself.
The linked repository is not archived, which leaves a path for maintenance, but it was last pushed about 8 years and 9 months ago. The active status does not offset the observed lack of recent work.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
nesbot/carbon Version ^1.0 | — | — |
illuminate/auth Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* | — | — |
illuminate/http Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* | — | — |
illuminate/support Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.