The clear MIT license, focused four-file layout, and lack of install scripts make the package straightforward to inspect. Its tiny community and missing security policy provide little reassurance for a package that has not changed in years.
43%
Total Score
25
100
78
83
The package has made no release in nearly five years: all four releases occurred around its first release on November 21, 2021. That long period without a new release is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the last push occurring nearly five years ago. This is a substantial abandonment risk for a dependency.
The repository is owned by a user account rather than an organization, so there is no visible organizational backing to compensate for the small maintainer base or stalled activity.
The repository has one star, zero forks, and zero watchers, showing very little independent adoption or community visibility. Popularity is supporting evidence rather than a verdict, but here it reinforces the maintenance concern.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are present. The missing scanning is a modest transparency and maintenance gap rather than proof of a defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^6.0|^7.0|^8.0 | — | — |
jenssegers/mongodb Version >=3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.