The repository is not archived, and the package includes tests, a README, and a matching source project. Its small dependency set and MIT license help, but do not offset the lack of a maintained release path.
22%
Total Score
50
67
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a serious adoption risk because the registry explicitly signals that dependents should move away from it.
The package has only one release, published about 5 years and 7 months ago, with no releases in the last 12 months. This provides little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the stale release history, this indicates an inactive maintenance path.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene concern rather than evidence that the release is unsafe by itself.
The only workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all 3 action references are unpinned, which is a supply-chain hygiene weakness, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ~5.6.40|~5.7.29|~5.8.38|^6.0 | — | — |
s1lentium/iptools Version ^1.1 | — | — |
illuminate/contracts Version ~5.6.40|~5.7.29|~5.8.38|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.