The repository has no security policy or security-scanning tools, which leaves maintenance and disclosure practices unclear. A clear MIT license, tests, documentation, stable release, and matching repository provide useful adoption support.
55%
Total Score
0
100
81
83
There were no commits or active maintainers in the last three months, consistent with the repository having been inactive for nearly six years. This materially increases abandonment and compatibility risk.
The latest release was nearly six years ago, with no releases in the previous 12 months. The package has an established history with 18 releases, but its current maintenance appears inactive.
Composer is used for builds, but no security-scanning tools are configured. The build setup is present, while security-process visibility is limited.
The linked repository is not archived, although it was last pushed nearly six years ago. The unarchived status provides some continuity but does not offset the prolonged inactivity.
The repository has no security policy, so reporting and handling of vulnerabilities are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~5.0|~6.0|^7.0 | — | — |
illuminate/support Version ~5.6.0|~5.7.0|~5.8.0|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.