The MIT license, readme, release notes, tests, and matching organization-owned repository provide useful transparency. Unpinned workflow actions and no security policy add smaller maintenance concerns; choose a maintained replacement if one is available.
35%
Total Score
75
71
50
Packagist marks the entire package as abandoned, with no replacement listed. This is a major warning for a new dependency even though the source repository remains available.
The package has 40 releases since 2015, but none in the last 12 months and its latest registry release was in May 2024. That indicates the published package is no longer receiving regular updates.
The repository recorded zero commits and zero active maintainers in the last three months. This supports the abandonment concern, despite a later repository push being recorded separately.
No repository security policy was found. For a small Composer library this is a secondary gap, but it reduces transparency about vulnerability reporting.
The assessed release is stable and not a prerelease, which supports maturity, although the reported latest registry version is v3.2.2 and does not align cleanly with the assessed v5.0.2.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/iso3166 Version ^3.0 | — | — |
illuminate/view Version ^7.0|^8.0 | — | — |
guzzlehttp/guzzle Version ^6.3.1|^7.0.1 | — | — |
illuminate/config Version ^7.0|^8.0 | — | — |
illuminate/support Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.