It includes tests, a readable README, a stable release, and no install-time scripts. However, repository activity stopped about ten months ago, the project has one maintainer, and the declared MIT license conflicts with the detected Apache-2.0 license file.
58%
Total Score
33
100
72
75
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the last push being about ten months ago, this is the strongest abandonment warning.
The manifest declares MIT, but the artifact and repository license file was detected as Apache-2.0. The mismatch creates avoidable licensing uncertainty despite the presence of a license file.
Only one account has registry publish access. That is a thin publishing base for a user-owned project and increases continuity risk if the maintainer becomes inactive.
The repository is owned by an individual user rather than an organization. This is consistent with the single registry maintainer and offers limited visible organizational continuity.
The package is about ten months old and has five releases, all within its first few weeks, with no later release shown. This indicates an initially active but now quiet release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.