Risky to adopt: the package has had no release for more than six years and no recent repository activity. It remains licensed, tested, and backed by a matching organization repository, but its maintenance appears effectively dormant.
42%
Total Score
50
100
67
75
Only three releases were published, all during January 2020, with no releases in the last 12 months. The long period without a release is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the latest push having been more than five years ago. This strongly lowers confidence that defects or compatibility issues will be addressed.
The repository is not archived, which is a positive, but its last push was more than five years ago. The non-archived status does not compensate for the prolonged inactivity.
No repository security policy was found, leaving vulnerability-reporting guidance unclear. This is a transparency gap, though it is less serious than the package's prolonged inactivity.
The workflow does not declare top-level token permissions. No write permissions were observed, but the lack of an explicit least-privilege declaration is a minor workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0.2 | — | — |
illuminate/support Version ^6.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.