The package is small, clearly linked to its own repository, and has a stable version with a simple dependency profile. Its lack of tests and security tooling leaves little evidence of ongoing quality control, so pinning this release should be approached carefully.
45%
Total Score
25
100
78
75
The package has had no releases in the last 12 months, and all six releases were clustered on 24 October 2024. This is a substantial maintenance concern for a package intended to integrate with a live API.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push on 24 October 2024. That strongly increases abandonment risk, although the repository is not archived.
The package and repository are owned by the same individual account. This provides clear ownership, though it does not show organizational backing or a broader maintenance base.
The repository has 0 stars, 0 forks, and 1 watcher, providing little supporting evidence of community review or shared maintenance capacity. Low popularity alone is not disqualifying, but it reinforces the thin maintenance picture.
Composer is used for builds, which is appropriate, but no security-scanning tools are present. For a small integration package this is a modest transparency and quality-control gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.