The single registry maintainer and four lifecycle scripts leave little operational margin. The package includes tests and a usable README, but its license is unresolved.
30%
Total Score
50
50
70
50
The latest release was over five years ago, with no releases in the last 12 months and only eight releases overall. This is strong evidence of abandonment risk.
The package declares 19 runtime dependencies, including several application integrations and related Zengine packages. This creates a broad compatibility and maintenance surface for an already stale release.
No declared license, license file, or detected license is present. That creates a material legal and adoption barrier for downstream users.
The package defines four lifecycle scripts, including post-install and post-update actions. These increase installation complexity and reduce reproducibility, although they are not by themselves proof of unsafe behavior.
Only one registry account has publish access. With no recent releases to show active maintenance, this creates a thin operational and bus-factor profile.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.1 | — | — |
fideloper/proxy Version ^4.0 | — | — |
laracasts/flash Version ^3.0 | — | — |
laravel/framework Version ^6.0 | — | — |
nunomaduro/collision Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.