MIT licensing, tests, release notes, and a small dependency set provide useful transparency. The project shows no active maintenance, leaving future compatibility and fixes uncertain.
12%
Total Score
50
57
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The package has 26 releases since 2017, but none in the last 12 months and the latest release was over 2 years ago. Earlier release activity does not compensate for the current halt.
There were no commits and no active maintainers in the last 3 months. Together with the archived repository, this indicates maintenance has stopped rather than merely slowed.
The source repository is archived, which prevents normal ongoing maintenance; its last push was over 2 years ago. This strongly increases abandonment and compatibility risk.
The repository has no security policy. This is a transparency gap, although it is secondary to the package's abandoned status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version >=5.5 <12.0 | — | — |
laravel/framework Version >=5.5 <12.0 | — | — |
saritasa/transformers Version 1.2.2 | — | — |
api-ecosystem-for-laravel/dingo-api Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.