The package is small, clearly tied to its source repository, and has a usable README with release notes. Its sole release and inactive repository leave little evidence of ongoing maintenance, while the missing tests and security tooling reduce assurance.
42%
Total Score
38
100
72
83
This is the package's only release, published over three years ago, with no releases in the last 12 months. That provides little evidence of continued maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push being over three years ago. This is strong evidence of abandonment risk.
Only one registry publishing account is listed. That is a limited publishing base for a user-owned project and offers little redundancy if the maintainer becomes inactive.
The repository is owned by an individual user rather than an organization, so the single-maintainer and inactivity concerns are not offset by visible organizational backing.
There are no open issues or pull requests and no activity in the last month. With no release or commit activity either, this looks inactive rather than actively quiet.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.