A clear README, tests, MIT licensing, and release notes make the package straightforward to evaluate and integrate. The small release history, absent security policy, and unpinned workflow actions weaken confidence in ongoing care and build hygiene.
44%
Total Score
33
50
78
50
The package has only 3 releases, all clustered within minutes on September 5, 2024, and none in the following 12 months. This provides weak evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the September 2024 last push, this is strong evidence that maintenance has stopped.
Eight runtime dependencies, including Laravel components, Predis, and the Swoole extension, reflect a substantial integration surface. The profile is plausible for a Laravel server package but increases maintenance exposure.
The package runs a post-autoload-dump lifecycle script during installation. This adds execution surface and warrants caution, although the signal does not establish that the script is harmful.
The package and repository are owned by the same individual account rather than an organization. This is not inherently unhealthy, but it offers limited evidence of institutional maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.1 | — | — |
illuminate/http Version >=5.4 | — | — |
laravel/framework Version >=5.4 | — | — |
illuminate/console Version >=5.4 | — | — |
illuminate/support Version >=5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.