The small six-file package is documented and easy to inspect, with no install-time scripts or suspicious workflow activity. Its MIT declaration and stable v1.0 improve clarity, but the absence of tests and security scanning leaves limited assurance for a Laravel dependency.
38%
Total Score
50
72
75
The package has had only one release, published in December 2018, with no releases in the last 12 months. That long lack of release activity is strong evidence of abandonment risk.
Only one registry maintainer is listed, leaving little visible publishing redundancy. This is a modest resilience concern for an independently owned project.
The repository is owned by an individual user rather than an organization, and no broader project backing is shown. That provides limited continuity if the maintainer stops maintaining the package.
The repository has 2 stars, 1 fork, and 1 watcher, indicating a small user and contributor footprint. Popularity is supporting evidence, but these counts provide little evidence of ongoing project capacity.
Composer is used as the build tool, but no security scanning tools are present. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.