The package has a README, tests, a matching repository, and no install-time scripts. Its last release was over 12 years ago and the repository has had no commits or active maintainers in the past 3 months, making maintenance uncertain.
42%
Total Score
50
75
75
Only one registry account has publish access, and the project is backed by an individual rather than an organization. This is a thin maintenance base, though registry access alone does not establish actual activity.
The package has made no release in over 12 years; only three releases were published, all clustered at the start of the project. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers during the last 3 months. Combined with the release history, this materially increases abandonment risk.
Composer is used for builds, but no security scanning tooling is present. That is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This matters for a package that performs application integration, even though it is not a severe issue by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 4.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.