The project has tests, a usable README, and organization backing, but its large dependency set and lack of security scanning add maintenance burden. Pin this release only for legacy Laravel 5.4 applications; it is not a good choice for new projects.
35%
Total Score
75
50
81
50
The latest release was published about nine years ago, with no releases in the last 12 months. The package is not deprecated, but this prolonged release inactivity is a substantial abandonment concern.
The package declares 18 runtime dependencies, including framework and Doctrine integrations, creating substantial compatibility and maintenance surface for an old Laravel 5.4 project. The profile does not show a minimal, low-maintenance package.
The repository has no new issues, pull requests, or merged pull requests in the last month, consistent with the release history showing no recent maintenance. A zero open-issue count does not compensate for the absence of activity.
Composer build tooling is present, but no security-scanning tooling is configured. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the absence of a policy is less significant than the much longer maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.30.0 | — | — |
predis/predis Version ~1.1 | — | — |
beberlei/assert Version ~2.7 | — | — |
twig/extensions Version ^1.3.0 | — | — |
laravel/framework Version ~5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.