The package includes tests, a changelog, a clear MIT license, and a repository that matches its name. Its small dependency footprint and stable release help, but the long pause in releases and commits raises maintenance risk.
57%
Total Score
50
100
92
50
The package uses a post-autoload-dump install-time script. This adds execution during installation and warrants attention, but the signal alone does not show harmful behavior.
The package has made no release in the last 12 months, despite four releases since November 2024; this is a meaningful sign of slowing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the risk that maintenance has stalled.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, though it is a hygiene concern rather than evidence of abandonment by itself.
Both analyzed workflows completed auditing with no reported findings or untrusted checkouts, but all two action references are unpinned, leaving them exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/pulse Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.