It has a clear MIT license, a useful README, tests in the repository, and a matching organization-backed source project. Its workflow audit found no dangerous patterns, but these positives do not offset the maintenance and deprecation concerns.
20%
Total Score
50
58
50
Packagist marks the entire package as abandoned and names always-open/laravel-process-stamps as its replacement. Package-level deprecation is a severe adoption concern.
The latest release was published about 5 years ago, with no releases in the last 12 months. The historical 25-release cadence shows prior activity but does not compensate for the prolonged pause.
The repository recorded no commits and no active maintainers in the last 3 months. Combined with the old latest release, this indicates the project is no longer being actively maintained.
The repository is not archived, and it was last pushed about 4 years ago. This avoids the strongest repository-level abandonment signal but does not offset the lack of current activity.
The single workflow was fully analyzed with no dangerous audit findings, untrusted checkouts, or script injection. However, all 3 action references are unpinned, a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.