The MIT license, repository tests, and straightforward Composer dependencies make the package easy to inspect. Its sole release is about six years old, with no commits in the last three months and no security scanning, leaving ongoing support uncertain.
38%
Total Score
25
100
75
100
The package has only one release, published about six years ago, with no releases in the last 12 months. This is strong evidence of limited maintenance and materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the package's long release gap. No compensating recent maintenance is shown.
The registry namespace and repository owner match, providing consistent ownership context. The owner is an individual account, so the single registry maintainer offers limited visible organizational redundancy.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a standalone reason to reject the package.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was about six years ago. The inactive history still warrants concern when combined with the release record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/config Version ^8.0 | — | — |
illuminate/support Version ^8.0 | — | — |
illuminate/database Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.