It has a clear MIT license, a usable README, and matching organization-backed source. Its dependency set is fairly broad, while no security scanning or policy is present.
38%
Total Score
50
50
71
50
The package has had no release in about 7 years, with zero releases in the last 12 months. Its earlier rapid release interval does not compensate for the prolonged halt.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the last push being about 7 years ago. This is strong evidence of abandonment risk.
The package declares 11 runtime dependencies for a minimal Laravel JSON API library, increasing maintenance and compatibility exposure. The dependencies are relevant to its stated framework integration, so this is a moderate concern rather than a severe one.
Composer build tooling is present, but no security scanning tools were detected. This leaves a transparency and maintenance-control gap.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, although it is secondary to the much older maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.1 | — | — |
illuminate/http Version 5.8.* | — | — |
optimus/heimdal Version ~1.0 | — | — |
illuminate/routing Version 5.8.* | — | — |
illuminate/support Version 5.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.