The package has tests, release notes, a clear MIT license, and only two runtime dependencies. Organization backing and an unarchived repository help, but the lack of security tooling leaves little additional assurance.
44%
Total Score
50
100
81
75
The package has had no releases in nearly seven years, despite four releases earlier in its history. This long period without updates is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last-push date, this indicates no recent maintenance capacity.
Composer is used as the build tool, but no security scanning tools are configured. That is a transparency and assurance gap, though it is less severe than the maintenance signals.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a real but secondary weakness for a small package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~5.5.0|~5.6.0|~5.7.0|~5.8.0|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.