A single maintainer and no commits in the last three months limit confidence in ongoing support. The repository includes 79 passing tests and release notes for this fix, but it has no security policy or scanning setup.
61%
Total Score
50
100
88
50
The registry lists one maintainer, and the repository is user-owned rather than organization-backed, leaving a thin apparent support base.
The package is about five months old, with three releases clustered within roughly two hours and no broader release history, so long-term maintenance is not yet demonstrated.
The repository recorded zero commits and zero active maintainers during the last three months, a concrete sign that maintenance may have stalled after the initial release burst.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-maintenance gap for middleware intended to protect applications.
The repository has no security policy, which makes reporting and handling vulnerabilities less transparent for a security-focused package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.