The small codebase is clearly packaged and licensed, with no install-time scripts or repository workflow exposure. Its age and lack of recent activity make it a legacy dependency; prefer a maintained Laravel installer or isolate and pin this version.
36%
Total Score
38
78
83
Only two releases exist, and the latest was published in May 2017; there have been no releases in roughly nine years. This is strong evidence of abandonment for a framework integration package.
There were zero commits and zero active maintainers in the last three months, while the last known repository push was in May 2017. This is the strongest maintenance warning in the collected evidence.
There is one registry maintainer. Because the repository is user-owned rather than organization-backed, this indicates a thin maintainer base and limited continuity.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the single-maintainer profile.
There are no open issues or pull requests and no activity in the last month. Combined with the old release date, the absence of current interaction supports an abandonment concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.