Recent repository activity has stopped, and the automated workflows use unpinned actions with a high-confidence bot-check issue. The package is documented, licensed, tested in the repository, and not deprecated or archived.
60%
Total Score
50
100
81
75
The repository is owned by a user account rather than an organization, so the single registry maintainer does not have visible organizational backing to offset the thin ownership base.
The package is young, with 3 releases over about 15 days and no release since May 1, 2026; this shows an initial cadence but limited maturity.
There were 0 commits and 0 active maintainers in the last 3 months, a meaningful sign that maintenance has currently gone quiet.
The repository has 0 stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not determine the health of a small package.
No security policy is present, leaving the process for reporting vulnerabilities unclear; this is a transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phunky/laravel-messaging Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.