Risky to depend on this release. It has had no new release in over two years, only three releases overall, and its README is still an uncustomized GitLab template, while repository transparency is limited.
42%
Total Score
50
50
60
100
The latest release was published over two years ago, with no releases in the last 12 months and only three releases since April 2024. This is strong evidence of stalled maintenance for a reusable framework package.
Six runtime dependencies, including framework and event-sourcing components, create meaningful compatibility and maintenance surface area. No development dependencies are declared, leaving limited evidence of an in-package development or testing setup.
Only one registry account has publish access. Administrative access is not proof of activity, but the single-publisher profile provides little redundancy alongside the absence of recent releases.
The package includes a substantial 6,216-character README, but the content remains largely an unedited GitLab starter template and provides little package-specific guidance. Missing tests and changelog files are not concerns because they are normally kept in the source repository rather than published artifacts.
Version 0.0.5 is not a stable major release, indicating an immature API and potentially higher compatibility risk for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0 | — | — |
spatie/laravel-data Version ^4.4 | — | — |
tucker-eric/eloquentfilter Version ^3.3 | — | — |
vitrin-infrastructure/types Version ^0 | — | — |
spatie/laravel-event-sourcing Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.