Risky to adopt: the package has had only one release and no repository commits for nearly three years. It is documented and licensed, but its unmaintained state and lack of a security policy are significant concerns for a package that exposes shell commands through a browser.
45%
Total Score
25
100
79
83
There has been only one release, on October 10, 2023, with no releases in the last 12 months. This indicates a very limited maintenance history and raises abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with no development since October 2023. This is a substantial abandonment concern.
The registry namespace and repository owner match, and the repository is owned by a user rather than an organization. This supports ownership consistency but provides limited maintainer backing.
Composer is used as a build tool, but no security scanning tools are configured. For a package that enables browser-based shell command execution, the missing security tooling is a meaningful transparency and maintenance gap.
The repository has no security policy. That is a notable gap for a package whose stated functionality exposes server command execution through a web application.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~5.7.0|~5.8.0|^6.0|^7.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.