Usable with caveats: the release is mature and backed by an organization, with tests, documentation, and release notes, but registry releases stopped in April 2023 and recent commit activity is absent. The missing license and limited repository security hygiene add adoption concerns.
68%
Total Score
83
100
83
70
One pull_request_target workflow is present. No untrusted checkout or script-injection patterns were detected, so the workflow warrants review but does not indicate a severe risk on its own.
No declared license or license file was found in the package or repository. That creates a real legal and transparency concern for a dependency.
The package has 27 releases over more than six years, but its latest registry release was in April 2023 and it had no releases in the last 12 months. This is a meaningful maintenance concern despite the historically regular release cadence.
There were no commits and no active maintainers in the three months measured. This weakens confidence in ongoing maintenance, although the repository was pushed in September 2025.
Composer build tooling is present, but no security scanning tools were detected. For a small package this is a hygiene gap rather than evidence that the package is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0 | — | — |
symfony/sendgrid-mailer Version ^6.0 | — | — |
spatie/laravel-mailcoach Version ^6.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.