A single registry maintainer and no security policy leave limited evidence of ongoing support. The package is licensed, tested, non-deprecated, and not archived, which offsets some risk but not the long maintenance gap.
38%
Total Score
25
75
75
The latest release was on September 30, 2019, with no releases in the last 12 months; the 25-release history shows earlier activity but does not offset more than six years of silence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no observed current maintenance.
Only one account has registry publish access, leaving a thin publishing base. This is especially concerning alongside the absence of recent release and commit activity.
Composer build tooling is present, but no security-scanning tools were detected; this is a hygiene gap rather than evidence that the release is unsafe by itself.
The repository has no security policy, reducing transparency about vulnerability reporting and response for a package with no recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ruflin/elastica Version ^6.0 | — | — |
illuminate/support Version ^5.6|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.