The README, exact repository match, and release notes provide useful consumer context. A single publisher, no security policy, and no recent repository activity reduce confidence in ongoing support.
38%
Total Score
50
50
75
67
The latest release was published in November 2021, and there were no releases in the last 12 months; this is a strong sign of abandonment for a package intended as an active dependency.
There were zero commits and zero active maintainers in the last three months, confirming that development activity has stopped rather than merely slowed.
The release declares eight runtime dependencies and no development dependencies. This is a meaningful integration surface, while the lack of dev dependencies provides little evidence of an actively maintained test or development setup.
Only one account has registry publish access. The organization-backed repository partly compensates for this thin registry publisher base, but it still leaves limited visible publishing redundancy.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the package cannot be maintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cocur/slugify Version ^4.0 | — | — |
nesbot/carbon Version ^2.54 | — | — |
mikecao/flight Version 1.3.* | — | — |
erusev/parsedown Version 1.7.* | — | — |
jenssegers/blade Version 1.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.