The license files disagree, and all three workflow actions are unpinned. The repository still has tests, release notes, and no install scripts, but these positives do not offset the maintenance warning.
30%
Total Score
0
17
67
The package includes a substantial README, changelog, tests in the repository, and release notes, but the README explicitly says the package is abandoned and should not be used.
This is the only release, published 105 days ago, with no subsequent releases; the single-release history provides little evidence of an established maintenance track record.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the package's abandonment notice and indicating no current maintenance capacity.
An MIT manifest declaration is contradicted by a detected GPL-3.0 license file, although license files are present in both the artifact and repository. The discrepancy needs resolution before adoption.
The repository has no security policy. This is a transparency gap for a package that is no longer maintained, because there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.1 | — | — |
illuminate/console Version ^v9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^v9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/filesystem Version ^v9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.