A single publishing maintainer, no license, and no security policy leave little resilience or transparency. The release is stable and has release notes, but that does not offset the lack of ongoing activity.
10%
Total Score
50
57
83
Packagist marks the package as abandoned at package scope, with no replacement provided. This is a severe adoption risk because future maintenance is not expected.
The repository had zero commits and zero active maintainers in the last 3 months, consistent with abandonment rather than active maintenance.
The linked repository is archived, confirming that the source project is no longer intended for active development. Its last push was about 23 months ago.
Neither the package nor the linked repository declares or contains a recognized license file. This leaves the legal terms for adoption unclear.
The package has 129 releases since May 2021, but none in the last 12 months; the latest release was about 23 months ago. Earlier release volume does not compensate for the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
goodby/csv Version 1.2.0 | — | — |
laravel/helpers Version ^1.2 | — | — |
laravel/framework Version 8.x|9.x|10.x|11.x | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.