Risky to adopt: this package has had only one release and no repository activity for over three years. It has useful basics such as a README, tests, a declared MIT license, and no deprecation, but the lack of ongoing maintenance makes future compatibility and support uncertain.
45%
Total Score
25
100
72
90
The package has had only one release, published over three years ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance or compatibility work.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was over three years ago. This is strong evidence of abandonment risk.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization. The matching ownership supports authenticity, while the individual backing offers limited maintenance capacity.
The repository has zero stars and forks and only one watcher. Popularity is not required for a small package, but these counters provide no supporting evidence of an active user or contributor community.
Composer is used for the build, but no security scanning tools are configured. This is a modest transparency and maintenance gap for a library distributed as a dependency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.