The README, tiny dependency surface, and lack of install scripts make its behavior easy to inspect. Confirm compatibility with your Laravel version and licensing terms before adoption.
43%
Total Score
25
100
70
75
The package has had no release in about nine years: its latest release was in August 2017, despite six releases during its first few months. That long gap is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and showing no recent maintenance capacity.
The manifest declares MIT, while the artifact license file is detected as Apache-2.0. Although a license file exists, the mismatch creates a real legal ambiguity for adopters.
One registry maintainer is consistent with a small user-owned package, but it provides little redundancy when combined with the absence of recent commits.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it is less serious than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 4.*|5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.