The package includes a matching MIT license, repository tests, a changelog, and a stable release. Its single-user project has had no release or commit activity for over three years, making abandonment the main concern.
45%
Total Score
0
81
83
The latest release was over three years ago, with no releases in the last 12 months and only two releases recorded. This is strong evidence of a stale package and is not offset by its stable version status.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This substantially raises abandonment risk.
The repository uses Composer, but no security scanning tooling was detected. This is a modest hygiene gap, not evidence that the package is unfit by itself.
No security policy was found in the repository, reducing transparency for vulnerability reporting. This matters for a maintained library, though it is secondary to the inactivity concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ~5.7.0|~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
illuminate/support Version ~5.7.0|~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
illuminate/database Version ~5.7.0|~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
illuminate/contracts Version ~5.7.0|~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.