It has tests, a changelog, a README, and a stable release with a small dependency set. Its single-user ownership and lack of security scanning provide little additional assurance for future fixes.
12%
Total Score
100
43
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
The package has 16 releases since June 2018, but none in the last four years; the latest release was in February 2022. This indicates prolonged inactivity.
The linked repository is archived and was last pushed in February 2022, so normal maintenance and issue response should not be expected.
The repository has two stars, no forks, and no watchers. Popularity is not decisive, but these figures provide little supporting evidence of broad community oversight.
Composer is used for builds, but no security scanning tool was detected. This is a modest assurance gap, especially for a package that is no longer actively maintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=6.0 | — | — |
illuminate/contracts Version >=6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.