The README and matching repository make the package understandable, and installation has no lifecycle scripts. However, releases and commits stopped roughly 2 years 7 months ago, while the license declaration conflicts with the Apache-2.0 license file and the project has very little adoption evidence.
48%
Total Score
50
67
83
The package has had no releases in the last 12 months, and its latest release was roughly 2 years 7 months ago. Its earlier median interval of about 13 days shows that this is a substantial interruption rather than an intentionally slow cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and raising abandonment risk.
The artifact includes an Apache-2.0 license file, so the release is licensed, but the manifest declares it as proprietary. That mismatch creates avoidable legal ambiguity for dependents.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of community review or shared maintenance.
The linked repository has no security policy and no security-scanning tools. This is a transparency and vulnerability-reporting gap, though it is less serious than the maintenance slowdown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.