Clear documentation, licensing, and a substantial release history support adoption. Recent repository work has stopped for three months, with one registry maintainer and no security policy or scanning, leaving maintenance capacity modest.
67%
Total Score
50
89
67
A post-autoload-dump script is present, adding install-time behavior that should be understood by adopters, but this is common Composer package integration and is not severe on its own.
Only one account has registry publish access, limiting visible publishing redundancy. This is partly consistent with the linked user-owned repository, but still leaves a thin maintainer base.
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful maintenance concern even though registry releases continued earlier.
The repository has two stars, zero forks, and one watcher, providing little evidence of broad external review or adoption. Popularity is supporting evidence only, so this is a modest concern rather than a verdict.
Composer build tooling is present, but no security scanning tools were detected, reducing automated supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.