The package is licensed, tested, documented, and clearly tied to its source repository. Maintenance has stalled since January 2025, with no recent commits and no security tooling or policy; one maintainer also limits resilience.
62%
Total Score
50
100
89
88
The repository recorded zero commits and zero active maintainers in the last three months, showing that current maintenance activity has stopped.
A single registry maintainer is consistent with the linked user-owned repository, but it leaves limited publishing redundancy if that maintainer becomes unavailable.
The package has 25 releases since May 2021, but none in the last 12 months and the latest release was in January 2025, indicating a long release gap.
There is only one open issue, with no issues or pull requests opened or closed in the last month; this is quiet rather than strong evidence of active support.
Composer build tooling is present, but no security scanning tools were detected, leaving security-oriented maintenance less visible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.1 | — | — |
firebase/php-jwt Version ^6.10 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
laravel/framework Version >=11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.