Risky to adopt: the package has had no release or repository commit in roughly nine years, indicating likely abandonment. It remains small and transparent, with a matching repository, README, tests, and an MIT license, but those positives do not offset the lack of maintenance.
40%
Total Score
0
100
71
83
The latest release was published in May 2017, with no releases in roughly nine years. This long period without updates is a substantial abandonment risk for a framework integration.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and providing no evidence of ongoing maintenance.
The repository has only 3 stars, 5 forks, and 1 watcher, indicating limited community visibility. Popularity is supporting evidence rather than decisive, but it offers little compensating maintenance capacity.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a transparency gap, although it is secondary to the much more serious maintenance concern.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is a secondary concern for this small package compared with its prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
geerlingguy/ping Version ^1.0.0 | — | — |
illuminate/support Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.