The artifact is substantial, licensed, tested, and documented, with a matching repository and release notes. Its large runtime dependency set and install-time scripts add upkeep and execution complexity.
43%
Total Score
25
50
75
50
The package has 75 releases, but none in the last 12 months; its latest registry release was nearly seven years ago. This long release gap is a serious abandonment concern despite the historically active cadence.
The repository recorded zero commits and zero active maintainers in the last three months. That supports the concern that the package is no longer actively maintained.
The package declares 15 runtime dependencies for a full Laravel and frontend application scaffold. That breadth increases maintenance and compatibility exposure, especially for a release that has not been updated in years.
The package runs three install-time Composer scripts, including project creation and setup hooks. Such scripts fit a project scaffold, but they increase installation complexity and the amount of package code executed during setup.
The repository is owned by the same individual namespace as the package rather than an organization. This is consistent ownership, but it provides less visible maintainer capacity than organization backing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dingo/api Version 2.0.0-alpha1 | — | — |
league/csv Version ^9.1 | — | — |
doctrine/dbal Version ^2.5 | — | — |
laravel/tinker Version ~1.0 | — | — |
tymon/jwt-auth Version 1.0.0-rc.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.