The package is clearly packaged, with tests, a changelog, an MIT license, and no install scripts. Its lone maintainer, very small user base, and absent security policy leave limited maintenance depth if compatibility or vulnerabilities emerge.
58%
Total Score
50
100
83
75
Only one account has registry publishing access. Because the repository is user-owned rather than organization-backed, this indicates limited publishing redundancy and increases continuity risk.
The package has 10 releases over more than 8 years, but none in the last 12 months; its latest release was over 3 years ago. This suggests a meaningful maintenance gap, though the historical cadence was previously established.
There were no commits and no active maintainers in the last 3 months. Combined with the older last push, this is evidence of a substantial current maintenance gap.
The repository has 2 stars, 0 forks, and 1 watcher. This is weak supporting evidence of adoption and suggests a small community, but popularity alone does not make the package unsafe.
The repository uses Composer but has no detected security-scanning tools. This is a hygiene gap rather than evidence of abandonment, especially since other project structure is present.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=8 | — | — |
illuminate/container Version >=8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.