The project has a recent compatibility release, a matching repository, clear MIT licensing, and a documented changelog. However, there were no commits or active maintainers in the last three months, and the repository has no security scanning or security policy.
63%
Total Score
50
100
88
75
The package and repository are owned by the same individual account, so the project has identifiable ownership but no demonstrated organizational backing. This is acceptable for a small package but gives it a thinner support base.
The package has existed for about 6 years 6 months with 19 releases, but only one release in the last 12 months. The recent release provides some evidence of ongoing maintenance, though the cadence is now sparse.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release partially offsets the abandonment signal.
There are only three open issues and no recent issue or pull-request activity. The small issue queue is not concerning by itself, but the lack of recent interaction provides little evidence of active support.
Composer is used for builds, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning reduces supply-chain transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.8|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.