Risky to adopt: the package has had no release or repository activity for about eight years, leaving compatibility and maintenance concerns. It is licensed, documented, and not deprecated or archived, but those positives do not offset the prolonged abandonment risk.
42%
Total Score
38
100
78
88
The latest release was published about eight years ago, with no releases in the last 12 months. This is strong evidence of an unmaintained dependency despite a historically active early release cadence.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long gap since the latest release. No provided activity signal compensates for this absence.
Only one registry account has publish access. A single maintainer can be sufficient for a small package, but here it provides little redundancy alongside zero recent repository activity.
The repository is owned by an individual user rather than an organization, so there is no organizational backing shown to compensate for the single-publisher and inactive-maintenance concerns.
One issue remains open, while there has been no issue or pull-request activity in the last month. Combined with the long maintenance gap, this suggests limited ongoing support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=5.3 | — | — |
pear/http_request2 Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.