The MIT license, substantial README, and narrow dependency set make the package straightforward to inspect and integrate. A single maintainer and no recent issue or pull-request activity provide little support evidence.
42%
Total Score
50
100
83
75
Only one account has registry publish access, leaving a thin operational base. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of broader project support.
The package has had no release in about 20 months, despite nine releases clustered on its first publication day. This is strong evidence of abandonment risk for a still-unmaintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance capacity.
The repository has zero stars, forks, and watchers, so there is little visible adoption or community support to compensate for the inactive maintainer.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or communicating security practices. This is a transparency gap, though it is less serious than the maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.