Documentation is minimal, and the project has no visible security process or recent development activity. Its stable version and matching source repository provide some reassurance, but the package is a poor long-term dependency choice.
38%
Total Score
50
69
75
No license declaration or license file was detected in the package or repository. This creates a serious transparency and reuse concern for downstream projects.
Only one registry maintainer is listed, leaving little visible publishing redundancy. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of broader maintenance capacity.
The package has no README, which matters for a Laravel integration package that consumers must configure and use. Missing tests and changelog files are not concerns because those normally belong in the source repository rather than the published artifact.
The latest release was about seven years ago, with no releases in the last 12 months and only two releases overall. That strongly suggests abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing roughly seven years of inactivity. This increases the risk that compatibility issues will remain unresolved.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.