The codebase is small and easy to inspect, with a clear README and only two runtime dependencies. Its lack of tests, security scanning, and an install-time script adds maintenance and review risk.
45%
Total Score
67
100
78
67
The package has only two releases, both within six days in June 2021, followed by more than five years without a release. This is strong evidence of abandonment risk despite the repository not being archived.
A post-install command runs during installation, adding execution and review surface beyond ordinary file installation. No provided signal shows that this script is unsafe or necessary, so it remains a caution rather than a severe finding.
The registry lists one maintainer, which is normal for an individually owned package but leaves limited visible publishing redundancy when combined with the stale release history.
There are no open issues or pull requests and no recent activity. While a quiet issue tracker can be healthy for a stable project, here it offers no counterweight to the long maintenance gap.
The repository has one star and no forks, providing little adoption evidence. Popularity is only supporting evidence, so this does not independently make the package unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ~7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.