Clear documentation, tests, and a permissive license reduce adoption friction. Maintenance and security visibility are limited, so pin this version and assess whether its stable API meets your needs.
62%
Total Score
50
100
88
83
A single registry maintainer indicates a thin publishing base, which increases continuity risk. The linked repository is user-owned rather than organization-backed, so there is no provided backing signal to offset it.
The package has had three releases, all within four days in November 2024, followed by no releases for nearly two years. This suggests maintenance has stalled despite an initially active release burst.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap. No provided activity signal compensates for this lack of recent maintenance.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a modest hygiene and maintenance concern rather than evidence of an unsafe release.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a security-process gap, but not severe enough to make the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^6.0|^7.0|^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.