The package has seen no release for about 8 years and no repository commits for over 7 years, leaving its Laravel and Pinterest API compatibility uncertain. Its license, documentation, and lack of install scripts are reassuring, but the single-person maintenance base and absent security policy add ongoing risk.
42%
Total Score
25
100
81
75
Only two releases were published, both in June 2018, with no releases in the last 12 months; the roughly 8-year gap is a strong abandonment concern.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating no recent maintenance.
One registry publishing account supports a thin maintenance base, with no provided organization backing to compensate for the concentration.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are configured; this is a minor hygiene gap alongside the broader maintenance concerns.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that makes API requests.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.