The package has a clear README, matching license file, tests in the repository, and release notes for this version. Its workflow audit found no dangerous patterns, but all six action references are unpinned.
15%
Total Score
67
100
64
83
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because future maintenance and support are not assured.
The linked source repository is archived, even though it was pushed recently. An archived repository is a strong sign that the project is no longer intended for active maintenance.
The package has five releases over about two years, but none in the last 12 months. The earlier release cadence is outweighed by the current lack of releases.
One contributor made all commits during the last three months, leaving maintenance dependent on a single active contributor. The repository is user-owned, so there is no shown organizational handoff capacity to offset this concentration.
Only one commit was recorded in the last three months, indicating very limited recent development activity. This provides little evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.