Package Health

php-laravel/framework

The package has clear licensing and no install-time scripts, but its source provenance is weak and its release history shows no follow-up activity. The linked repository has no security policy or scanning tools, leaving important maintenance gaps.

Latest v1.0.0PackagistPackagist

0%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free
Malware icon

Malware detected in 1 version

Latest:vv1.0.0, detected 2 years ago

Health Score Breakdown

Release historydanger

This is the only release, published 867 days ago, with no releases in the last 12 months. That strongly suggests abandonment or an unmaintained package.

Repo package mentioncaution

The repository name does not match the package name, although its README mentions the package. The README reference is compensating evidence, but the mismatch still leaves provenance less clear than a directly matching repository.

Repo popularitycaution

The linked repository has 0 stars, 0 forks, and 1 watcher. Popularity is not decisive, but these values reinforce the lack of visible project adoption or community backing.

Repo toolingcaution

Composer is used for builds, but no security-scanning tools are present. For a framework with 40 runtime dependencies, this is a meaningful supply-chain hygiene gap.

Security policycaution

The repository has no security policy. This is a maintenance and transparency gap for a framework package, with no provided evidence compensating for it.

Package versions

Maintainers

Taylor Otwell

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
—
—
brick/math
Version ^0.9.3|^0.10.2|^0.11|^0.12
—
—
ramsey/uuid
Version ^4.7
—
—
symfony/uid
Version ^6.2
—
—
symfony/mime
Version ^6.2
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform