The package includes tests, a changelog, release notes, a clear MIT license, and a small dependency surface. Its organization-backed repository has no security policy and shows no commits or issue progress since the initial release, so pinning this version deserves caution.
57%
Total Score
75
100
83
88
This is the only release, published about 10 months ago, with no subsequent releases. That limits evidence of ongoing maintenance and makes the release history a meaningful concern.
There were no commits and no active maintainers during the last three months, consistent with a project that has remained unchanged since its initial release. That weakens evidence of ongoing maintenance.
There is one open issue and no issues or pull requests were opened or closed in the last month. This is limited evidence of project activity and adds a modest maintenance concern alongside the lack of commits.
The repository has zero stars, forks, and watchers. For a package only about 10 months old this is supporting caution, not a standalone health verdict.
Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a hygiene gap, though it does not by itself show the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.