The artifact is small, readable, and MIT-licensed, with one runtime dependency and no install-time scripts. Its limited project safeguards leave little evidence of ongoing support for a dependency last updated years ago.
38%
Total Score
25
100
79
83
The package has only two releases, both published in September 2021, and none in the last 12 months. This is strong evidence of abandonment risk for a package intended as a maintained Laravel dependency.
The repository recorded zero commits and zero active maintainers during the last three months, with its last push in September 2021. This indicates prolonged inactivity and materially raises abandonment risk.
The linked repository is owned by an individual user rather than an organization. That is not inherently unhealthy, but it provides no visible organizational backing to offset the inactive project.
The repository has one star and no forks, showing very limited adoption or external support. Popularity is only supporting evidence, but this leaves little community backstop for an inactive package.
The repository has no security policy or documented vulnerability-reporting path. For a small package this is a hygiene gap, but it adds uncertainty when combined with the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.