Its MIT license, README, release notes, and repository tests make the code easier to evaluate. The single maintainer, absent recent releases or commits, and unsafe workflow automation add further adoption risk.
10%
Total Score
25
57
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
The package has had no release in over two years despite 17 historical releases, showing that registry maintenance has stopped.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the abandonment signals.
The linked source repository is archived, which indicates the project is no longer intended for normal ongoing maintenance even though it has a recorded push date.
Only one registry account has publish access, leaving little visible publishing redundancy. This is more concerning alongside the lack of recent releases and repository activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bkwld/croppa Version ^6.0 | — | — |
livewire/livewire Version ^2.12 | — | — |
illuminate/contracts Version ^10.0 | — | — |
blade-ui-kit/blade-icons Version ^1.5 | — | — |
blade-ui-kit/blade-heroicons Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.