The release has a substantial dependency surface and uses two unpinned workflow actions, while the repository has no security scanning or security policy. Its README, tests, release notes, and long release history provide useful context but do not offset the maintenance status.
10%
Total Score
25
50
50
Packagist marks the entire package as abandoned and points to a replacement repository, making this release unsuitable as a new dependency despite its otherwise established history.
The package has 279 releases since June 2015, but its latest registry release was in January 2022 and it had no releases in the last 12 months, showing that active publishing has stopped.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the archived and abandoned status.
The linked source repository is archived, which is a severe abandonment risk even though it was pushed recently enough to show historical activity.
There were no new or closed issues or pull requests in the last month, and no open work remains; this is consistent with an inactive project rather than evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^3.0 | — | — |
laravel/tinker Version ^2.5 | — | — |
laravel/sanctum Version ^2.11 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
laravel/framework Version ^8.54 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.