The package is clearly identified, licensed, and documented for consumers. Its small project has no tests or security scanning, and one maintainer leaves little evidence of ongoing support.
43%
Total Score
50
100
78
88
This is the package's only release, published over a year ago, with no releases in the last 12 months. That provides little evidence of continued maintenance for a dependency.
There were no commits and no active maintainers during the last three months, following a repository last pushed over a year ago. This is strong evidence of inactive maintenance.
One registry maintainer is consistent with an individual-owned project, but it also indicates a thin publishing base and limited apparent continuity capacity.
The repository has zero stars and forks and one watcher. Popularity is not required for a healthy package, but these counters provide no supporting evidence of adoption or community resilience.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools are configured, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.