Usable with caveats: the package is clearly identified, licensed, documented, tested in its repository, and not deprecated, but maintenance appears dormant. The last release was about four years ago, with no recent commits or issue activity, and repository workflow controls are weak.
56%
Total Score
33
100
78
70
There were zero commits and zero active maintainers in the last three months, indicating that maintenance has effectively stopped recently.
The repository has two pull_request_target workflows and one workflow with an untrusted checkout, creating elevated automation exposure. No script injection was detected, which limits the severity.
The package is linked to a personal GitHub account rather than an organization, so there is no organizational backing shown to compensate for its single registry maintainer or inactivity.
The package has 39 releases since 2019, but there have been no releases in the last 12 months and the latest release was about four years ago. That long release gap is a meaningful abandonment concern.
There are three open issues and three open pull requests, but none were created or merged in the last month. This suggests that outstanding work is not being actively handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.