The package is licensed, documented, and its source includes tests and security tooling. It has had one release, was abandoned by the registry, and its repository is archived with no recent commits. Choose an actively maintained replacement.
12%
Total Score
0
57
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk even though the deprecation is package-wide rather than limited to this release.
This is the package's only release, published over three years ago, with no releases in the last 12 months. The absence of a release cadence strongly increases abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. This supports the registry's abandoned status rather than showing ongoing maintenance.
The linked repository is archived and was last pushed in October 2023, indicating that active maintenance has ended. No provided signal compensates for the archived project state.
All 14 action references are unpinned, and a high-confidence, high-severity bot-conditions finding affects the Dependabot auto-merge workflow. The audit is complete, but these workflow weaknesses add supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^9.0 | — | — |
porifa/laravel-package-kit Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.