The repository has recent commits, tests, release notes, and an organization behind it. The workflow leaves all five action references unpinned and the project has no security policy, while package deprecation requires extra migration planning.
58%
Total Score
75
81
83
The package is marked abandoned on Packagist at package scope, with cnxapp/laravel-telegram listed as the replacement. This is a significant adoption and continuity concern even though the replacement repository is active.
Only one registry account has publish access, which creates publishing concentration. The linked repository is organization-owned, providing some maintenance backing.
All eight recent commits came from one contributor, giving the project a high operational bus factor risk. Organization ownership provides backing, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and vulnerability-detection gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.