The package has solid consumer documentation, tests, a changelog, and a matching MIT license. Its small audience, single publisher, missing security policy, and loosely pinned workflow actions add uncertainty.
58%
Total Score
50
100
78
67
Only two releases exist, both from April 2022, with no release in the last four years and five months. This is the strongest indication that maintenance has stopped.
The package and repository are owned by matching individual accounts rather than an organization. This does not prove a problem, but it offers less visible institutional backing for a project already showing prolonged inactivity.
There were no commits and no active maintainers in the last three months, consistent with the release history showing prolonged inactivity. The repository is not archived, so this is a serious maintenance concern rather than proof the package is unfit.
The repository has only two stars, two forks, and no watchers, indicating a small user base and limited external visibility. Popularity is supporting evidence, so this does not outweigh the maintenance signals alone.
Composer build tooling is present, but no security-scanning tools are reported. The missing scanning coverage is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^7.21 | — | — |
illuminate/support Version ^7.21 | — | — |
smi2/phpclickhouse Version ^1.3 | — | — |
illuminate/contracts Version ^7.21 | — | — |
illuminate/filesystem Version ^7.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.