The matching repository, MIT declaration, release notes, and lack of install-time scripts provide useful transparency. One maintainer, no tests or security tooling, and no activity for about seven years leave little evidence of ongoing support.
42%
Total Score
25
79
75
The package has only two releases, both published in August 2019, with no release in about seven years. That is strong evidence of abandonment for a package developers may need to maintain with current Laravel and PHP versions.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push having occurred in August 2019. No newer maintenance evidence compensates for this gap.
A single registry maintainer creates a thin publishing base, though the linked repository is owned by the same person and the package is small. This still leaves limited visible continuity if that maintainer stops supporting it.
Composer build tooling is present, but no security-scanning tools are configured. For an old package with no recent activity, the absence of automated security checks reduces maintenance transparency.
The repository has no security policy, making vulnerability reporting and response expectations unclear. This is a transparency gap, although it is less significant than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^3.0|^4.0 | — | — |
symfony/process Version ^3.0|^4.0 | — | — |
symfony/filesystem Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.