The README and MIT declaration make installation and licensing clear. There is no security policy or scanning, while the single-maintainer project offers limited support capacity.
42%
Total Score
25
79
50
The package has had no release in over six years, despite eight releases overall and a previously regular median interval of about 24 days. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no recent maintenance evidence.
Only one registry maintainer is listed, so the project has limited visible publishing capacity and a higher bus-factor risk if that maintainer stops supporting it.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy, reducing transparency about how vulnerabilities are reported and handled. This is a supporting hygiene concern rather than evidence of a security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^6.0|^7.0 | — | — |
ceddyg/query-builder-repository Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.