Its README explains setup, and the package has a narrow two-runtime-dependency footprint. The project says it is no longer maintained; releases stopped after February 2023, recent commit activity is zero, and 28 issues remain open. Missing security policy and scanning add transparency concerns.
38%
Total Score
33
100
78
83
The package has 28 releases, but its latest release was in February 2023 and it had no releases in the last 12 months. That long release gap is a meaningful maintenance concern for a library dependency.
There were zero commits and zero active maintainers in the last three months. For a package intended as a framework integration, that is strong evidence of abandonment risk.
The repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible organizational backing for continued maintenance.
The repository has 28 open issues but no new or closed issues in the last month and no pull requests. This supports the conclusion that maintenance and issue handling have stalled.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance hygiene gap, although it is less significant than the lack of project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.1|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.