The source repository has tests and a clear MIT license, but recent commit activity is absent and its registry identity is unclear. Pinning this release leaves you without an active package channel or security policy.
35%
Total Score
50
60
67
Packagist marks the entire package as abandoned and points to reliqarts/laravel-common. This is a serious adoption risk because the assessed package is no longer the recommended dependency.
The package has 37 releases, but its latest registry release was about 5 years ago and there were no releases in the last 12 months. The long earlier cadence does not compensate for the current release gap.
The repository recorded no commits and no active maintainers in the last 3 months. Although the repository was pushed in March 2025, current development activity is not demonstrated.
The linked repository name does not match the package name and its README does not mention this package. That weakens confidence that the repository is the maintained source for this exact registry package.
The repository has no security policy, leaving no documented channel for reporting vulnerabilities or explaining security response practices.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version 1.24 - 2 | — | — |
illuminate/support Version ^8.0 | — | — |
anhskohbo/no-captcha Version ^3.1 | — | — |
spatie/laravel-sitemap Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.