No commits or releases have appeared for more than four years, and the project has no security policy or scanning. The MIT license, tests, matching repository, and clean workflow audit provide useful transparency but do not offset the maintenance risk.
18%
Total Score
25
100
64
83
The package is explicitly abandoned on Packagist, with koffinate/laravel-core named as the replacement. This is a severe dependency-health risk for a new adoption.
The package has 36 releases but none in the last 12 months; its latest release was published more than four years ago. The earlier short median interval shows prior activity but does not compensate for the prolonged stoppage.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release pause and increasing abandonment risk.
The package and repository are owned by the same individual account. This confirms ownership alignment but provides only a thin backing structure for ongoing maintenance.
Composer is used as the build tool, but no security scanning tool is configured. The missing scanning reduces maintenance hygiene modestly without independently making the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0 | — | — |
illuminate/auth Version ^8.40|^9.0 | — | — |
illuminate/support Version ^8.40|^9.0 | — | — |
illuminate/database Version ^8.40|^9.0 | — | — |
illuminate/container Version ^8.40|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.