The MIT license, matching repository, tests, changelog, and readable package documentation provide useful transparency. Install-time scripts, absent security scanning, and more than two years without a new release make long-term maintenance and update safety concerns.
42%
Total Score
33
81
75
Only two releases exist, both published about 814 days ago, with no releases in the last 12 months. The short history and prolonged release gap materially increase abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with no release in over two years, this is strong evidence of inactive maintenance.
Four install or update lifecycle scripts run automatically, including post-create-project-cmd and post-update-cmd. This increases installation and update complexity because package code executes during common Composer operations.
The package and repository are owned by the same individual account rather than an organization. That is not inherently unhealthy, but it offers less visible organizational backing for a project with no recent activity.
There were no new or merged pull requests and no new or closed issues during the last month; with open issue count unavailable, this is supporting evidence of inactivity rather than proof of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^4.5.2 | — | — |
doctrine/dbal Version ^4.0.2 | — | — |
laravel/tinker Version ^2.9 | — | — |
laravel/sanctum Version ^4.0 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.