Risky to adopt: the package has had no release in about eight years and no recent repository activity. It still has a license, README, tests, and changelog, but those positives do not offset the strong abandonment risk.
39%
Total Score
0
71
50
The package was last released about eight years ago, with four releases overall and none in the last 12 months. This strongly suggests abandonment despite the early burst of releases.
There were no commits and no active maintainers in the last three months. Combined with the old last push, this is strong evidence that maintenance has stopped.
The package defines three install-time Composer lifecycle scripts, increasing installation complexity and the amount of code executed during setup. No provided signal shows these scripts are harmful, so this is a limited supply-chain hygiene concern.
Composer is used as a build tool, but the repository has no security scanning tools. This is a transparency and maintenance gap, though it is secondary to the much older activity evidence.
The linked repository is not marked archived, which avoids an explicit abandonment marker. However, its last push was about eight years ago, consistent with the stale release history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
curl/curl Version ^1.8 | — | — |
backpack/crud Version ^3.4 | — | — |
laravel/tinker Version ^1.0 | — | — |
fideloper/proxy Version ^4.0 | — | — |
google/apiclient Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.