The package has a clear MIT license, a matching repository, and a stable 1.0.1 release. Its tiny single-owner project has limited operational safeguards, so pinning this version is wiser than expecting ongoing fixes.
58%
Total Score
50
100
75
50
The package and repository are owned by the same individual account rather than an organization. Combined with one registry maintainer, this indicates limited visible project backing.
Only two releases exist, with no release in roughly 15 months and a long interval between releases. This indicates limited maintenance momentum, though it does not by itself prove abandonment.
There were no commits and no active maintainers in the last three months. This is direct evidence of currently inactive development and raises the risk that issues will remain unresolved.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy package, but these values provide little evidence of broad community support.
Composer is used for builds, but no security scanning tool was detected. The missing scanner is a modest transparency and maintenance gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.0.0|^9.0.0|^10.0.0|^11.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.