Risky to adopt: this package has had no release or repository activity for about 3 years and 6 months, leaving compatibility and maintenance uncertain. It is small, clearly licensed, and its repository matches the package, but those positives do not offset the prolonged inactivity.
45%
Total Score
0
71
75
The package has only one release, published about 3 years and 6 months ago, with no releases in the last 12 months. This is strong evidence of limited ongoing maintenance for a Laravel integration.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since its only release. No provided signal shows compensating maintenance activity.
The repository has 0 stars, 0 forks, and 1 watcher, providing little evidence of a broad user or contributor community. Popularity is supporting evidence rather than decisive on its own, so this is a caution rather than a standalone severe risk.
Composer build tooling is present, but no security scanning tools are configured. For a small package this is a transparency gap, though it is less important than the observed inactivity.
The repository has no security policy, reducing transparency about vulnerability reporting and maintenance expectations. This adds a modest concern but does not independently make the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/mail Version ^9.0|^10.0 | — | — |
illuminate/queue Version ^9.0|^10.0 | — | — |
illuminate/console Version ^9.0|^10.0 | — | — |
illuminate/support Version ^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.