The README, changelog, and matching source repository make the package straightforward to inspect and adopt. Its simple dependency profile limits exposure, but verify compatibility before relying on a release with no recent maintenance.
56%
Total Score
75
100
81
83
Only two releases are recorded, with none in the last 12 months; the latest release was published about 4.5 years ago. This materially raises abandonment and compatibility risk.
There were no commits and no active maintainers in the last three months, consistent with the long period since the last release and increasing abandonment risk.
The repository has one star, no forks, and no watchers, indicating very limited visible adoption and little independent validation.
Composer is used for the build, providing basic ecosystem-aligned tooling, but no security scanning tools are present. The missing scanning is a hygiene gap rather than a severe dependency risk.
The repository has no security policy. For a small utility this is a transparency and reporting gap, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.