The package has seen no release or commit activity for nearly nine years, making compatibility and maintenance uncertain. Its MIT license and matching repository are positives, but missing security scanning and install-time scripts add operational concerns.
35%
Total Score
0
70
50
The latest release was published nearly nine years ago, with no releases in the last 12 months; the earlier 22-release history does not compensate for the prolonged silence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
The package declares four install or update lifecycle scripts, which increase installation complexity and warrant extra review when adopting an old, inactive release.
Composer is used for builds, but no security scanning tools were detected. This is a secondary transparency and maintenance gap rather than evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zgldh/scaffold Version <1.0 | — | — |
zgldh/module-activity-log Version ^0.5.1 | — | — |
zgldh/laravel-upload-manager Version ~0.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.