Usable with caveats: the package is stable, clearly linked to its organization-backed repository, and not deprecated or archived. However, it has had no registry release in over a year, no commits in the last three months, no security policy, and uses a proprietary license.
58%
Total Score
75
81
50
The manifest declares a proprietary license and no license file is present. Although this is a license declaration rather than an unlicensed release, it may restrict use and is less transparent for an open-source dependency.
The package has 25 releases, but none in the last 12 months, despite being only about 17 months old. This prolonged release gap weakens confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of currently limited maintenance activity.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning capability reduces maintenance assurance, though it is not evidence that the package is unsafe.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a maintenance and transparency gap for a package with substantial framework and cloud-service functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.1 | — | — |
aws/aws-sdk-php Version ^3.336 | — | — |
laravel/sanctum Version ^4.0 | — | — |
kalnoy/nestedset Version ^6.0 | — | — |
laravel/framework Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.