The repository has had no commits for nearly five years, and the project provides no security policy or scanning. Its MIT licensing, focused dependency set, and matching organization repository are positives, but they do not offset the package withdrawal.
12%
Total Score
50
63
75
Packagist marks the entire package as abandoned and points to typicms/typicms as the replacement. This is a direct warning against taking a new dependency on this release.
The package has 94 releases since December 2014, but its latest release was in November 2021 with no releases in the last four years. The historical cadence does not compensate for the prolonged halt.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package having been inactive since November 2021.
Composer build tooling is present, but no security-scanning tools were detected. That weakens release and vulnerability hygiene, although it is secondary to the package's abandonment.
The repository is not formally archived, but its last push was in November 2021. This avoids the strongest archival warning while still supporting the evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ~8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.