Stable versioning, a small dependency footprint, and clear project ownership reduce adoption friction. The long release interval, no recent commits, absent security policy, and unpinned workflow actions warrant monitoring.
72%
Total Score
75
100
88
67
The package has only 3 releases across 847 days, with 1 release in the last 12 months and a median interval of about 329 days. This is slow but not abandonment by itself.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with the package's long release interval, this lowers confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tool was detected. That is a modest transparency and assurance gap for the project.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
All 4 workflows were analyzed with no audit findings or untrusted execution paths, but all 13 action references are unpinned. This is a workflow reproducibility and supply-chain hygiene weakness, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
blade-ui-kit/blade-icons Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.