The MIT declaration and readable README provide basic transparency. The install script and lack of repository security tooling add smaller maintenance concerns, while the package’s identity and long inactivity require particular caution.
34%
Total Score
0
69
50
Only two releases were published, both in January 2020, with no release in roughly six years. This is strong evidence of abandonment risk, although the package is not marked deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being in March 2021. The long inactivity materially reduces confidence in ongoing maintenance.
The package runs a post-root-package-install script, adding install-time behavior that consumers must account for. No provided signal shows that this script is necessary or compensating for the extra complexity.
The artifact includes a 1,412-character README and this version has a GitHub release; missing tests and a changelog in the package are normal packaging practice. The README content appears oriented toward a different framework, limiting its transparency value.
The linked repository name does not match this package and its README does not mention the package. That raises a concrete concern that the source repository may not actually publish or maintain this package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^7.1 | — | — |
league/fractal Version 0.17.* | — | — |
illuminate/mail Version 5.5.* | — | — |
vlucas/phpdotenv Version ~2.2 | — | — |
guzzlehttp/guzzle Version 6.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.