Risky to adopt: the latest release is more than nine years old and the repository has had no commits in over eight years. It has useful documentation, tests, and a stable MIT license, but the long-standing inactivity makes ongoing compatibility and maintenance unlikely.
38%
Total Score
0
100
75
75
The package has had no releases in the last 12 months, and version 1.3.2 was published more than nine years ago. This is strong evidence of abandonment risk despite the earlier seven releases arriving in a short period.
The repository recorded zero commits and zero active maintainers during the last three months, reinforcing that development has stopped rather than merely slowed.
The repository uses Composer, showing basic build tooling, but it has no security scanning tools. This is a modest transparency gap for a package that deploys applications to AWS Lambda.
The repository is not marked archived, which is a positive transparency signal, but its last push was more than eight years ago and therefore does not offset the inactivity evidence.
No repository security policy is present. This is a maintenance and disclosure-process gap, though it is less significant than the prolonged absence of releases and commits.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ~3.0 | — | — |
illuminate/console Version ^5.1 | — | — |
illuminate/support Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.