The package includes tests, a substantial README, and a matching MIT license. Its sole release was published over three years ago, with no recent commits and no security policy; the workflow also leaves all three actions unpinned.
42%
Total Score
50
100
69
67
This is the package's only release, published over three years ago, with no releases in the last 12 months. That lack of ongoing release activity is a substantial maintenance concern.
There were no commits and no active maintainers in the last three months, consistent with a project that has stopped receiving maintenance.
The repository is owned by an individual user rather than an organization. Combined with the single-release history and no recent commits, this provides little visible maintenance redundancy.
The repository has 12 stars and one fork, showing limited adoption. Popularity is supporting evidence rather than a verdict, so this only modestly lowers confidence in long-term maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, not severe evidence on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.5 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
illuminate/support Version ^9.36 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.