Clear documentation, tests, release notes, and a matching repository make this easy to evaluate and maintain. The long gap since the last release and three unpinned workflow actions add practical maintenance and build-integrity concerns.
70%
Total Score
67
88
83
A post-autoload-dump install script is present. This adds installation behavior that should be understood by consumers, but the signal alone does not show unsafe or unusual execution.
The package has 12 releases over roughly five years with a historical median interval of about 69 days, but no releases in the last 12 months; this indicates a meaningful maintenance slowdown.
There were zero commits and zero active maintainers in the last three months, a direct sign of currently stalled development. The recent repository push partly offsets abandonment concerns but does not show ongoing code activity.
There are no open issues and three open pull requests, but no issues or pull requests were merged in the last month; this offers limited evidence of active maintenance.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP package this is a hygiene gap rather than a standalone dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
orchestra/testbench Version ^9.0|^10.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.