Usable with caveats: this is a mature, organization-backed package with tests, release notes, and no deprecation, but it has had no release or repository activity for over five years. Treat it as a legacy dependency and verify compatibility with your current Laravel stack.
58%
Total Score
75
79
75
The package has a long history with 44 releases, but its latest registry release was over five years ago and it had no releases in the last 12 months. That substantially raises maintenance and compatibility risk.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the last release. This is the main ongoing-maintenance concern.
The repository uses Composer build tooling, but no security scanning tools were detected. That is a transparency gap, though the absence of scanning alone is not severe for this otherwise conventional package.
The linked repository is not archived, but it was last pushed over five years ago. The unarchived status is reassuring, while the old last-pushed date still indicates likely abandonment or dormancy.
The repository has no security policy, reducing guidance for reporting and handling vulnerabilities. This is a documentation gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orchestra/support Version ^6.0 | — | — |
illuminate/database Version ^8.37 | — | — |
orchestra/contracts Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.