The package includes tests, a README, and an MIT declaration, but the repository has no security policy or scanning tools. Its README does not identify this package, weakening confidence in the source relationship.
12%
Total Score
0
100
50
75
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk, not merely a withdrawn release.
The package has had no releases in about 4 years and 2 months, with zero releases in the last 12 months. This strongly supports the abandonment concern.
There were zero commits and zero active maintainers in the last 3 months. The archived state and long release gap leave no evidence of ongoing maintenance.
The linked repository is archived and was last pushed about 3 years and 6 months ago, indicating the source is no longer maintained.
The repository name does not match the package name, and its README does not mention this package. That weakens confidence that the linked repository is the package's actual source.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
bref/bref Version ^1.5 | — | — |
aws/aws-sdk-php Version ^3.224 | — | — |
bref/laravel-bridge Version ^1.2 | — | — |
samagtech/core-lumen Version ^1.0 | — | — |
flipbox/lumen-generator Version ^9.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.