The package has a clear source repository, stable version, and organizational backing. Its single release was nearly six years ago, with no recent commits, tests, changelog, or security policy, while the license declaration conflicts with the detected license.
42%
Total Score
50
100
71
83
This is the package’s only release, published nearly six years ago, with no releases in the last 12 months. That strongly raises abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and limited evidence of ongoing maintenance.
The artifact contains license files, but the manifest declares MIT while the detected license is Apache-2.0. The package is licensed, yet the mismatch creates avoidable legal uncertainty.
The published package and repository have no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README weakens consumer documentation for a Laravel library.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though the package’s small scope and organizational ownership provide limited context rather than a full remedy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.2 | — | — |
laravel/framework Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.