The small codebase has clear installation and usage guidance, a matching repository, and a valid MIT license. Its long release gap and lack of recent commits suggest limited ongoing maintenance, while one maintainer and no security scanning add modest concern.
62%
Total Score
50
100
88
75
One individual has registry publishing access, leaving a thin publisher base. For this small user-owned project that is a modest continuity concern, not evidence of abandonment by itself.
The registry namespace and repository are owned by the same individual, which supports ownership continuity but offers no organizational backing to broaden maintenance capacity.
The package has had no releases in over two years, with zero releases in the last 12 months. Its six-release history shows it was once maintained, but current maintenance appears slow.
The repository recorded zero commits and zero active maintainers in the last three months. Together with no release in over two years, this indicates limited recent maintenance.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than a severe dependency-health issue for this small package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~8.0 | ^9.0 | ^10.0 | ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.