The release is explicitly a proof of concept, with no tests and no security scanning to support ongoing maintenance. Its MIT license, focused file tree, README, and non-deprecated status provide useful baseline transparency.
38%
Total Score
0
67
50
This is the package's only release, published about 9 years ago, with no releases in the last 12 months. That strongly suggests the project is abandoned rather than actively maintained.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. No provided signal shows compensating recent maintenance.
The package includes a README and a GitHub release note describing it as a proof-of-concept, but it has no tests; the release note partly documents the version while the test gap weakens confidence in changes.
Composer is used for the build, which is appropriate, but the repository has no security scanning tools. Given the absence of recent maintenance, this is a meaningful hygiene gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This adds transparency risk for a package handling application profiling data.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
alanvaill/profiler Version dev-master | — | — |
illuminate/support Version ^5.3 | — | — |
illuminate/contracts Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.