The codebase is easy to inspect and uses a clear MIT license with no install-time scripts. Its very long inactivity and lack of tests or security policy make adoption a liability for a maintained application.
38%
Total Score
100
100
50
75
The latest release was in January 2017, and there were no releases in the last 12 months. This prolonged absence of releases is strong evidence of abandonment risk.
The package includes a README, but it is only 16 characters long, and the repository has no tests or changelog. Missing tests and changelog are not packaging failures by themselves, but they reduce confidence in this small library's maintenance quality.
The repository name matches the package, which supports the linkage, but the README does not mention the package. That weakens package-specific transparency despite the matching repository name.
The repository has zero stars and forks, with four watchers. Popularity is only supporting evidence, but these very low adoption indicators provide no compensating community signal for the long inactivity.
The repository is not archived, which avoids an explicit abandonment marker, but its last push was still in January 2017 and does not offset the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ~5.3.0|~5.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.