The linked project has tests, a clear MIT license, and was pushed in June 2024. Its repository does not identify or mention this package, and the last registry release was about six years ago, making long-term support uncertain.
46%
Total Score
50
100
69
83
The latest release was about six years ago, with no releases in the last 12 months. This is strong evidence of stale distribution maintenance, although the repository was pushed more recently.
The repository name does not match the package name and its README does not mention the package. That makes the package-to-source relationship difficult to verify and is a concrete transparency concern.
The package and repository are associated with individual-user accounts rather than an organization. This is not inherently unhealthy, but it provides less visible institutional backing for a package with stale releases.
There were no commits and no active maintainers in the three months measured. Combined with the old registry release, this raises current maintenance risk, though the repository was pushed about two years ago.
Composer build tooling is present, but no security scanning tooling was detected. The missing scanner is a modest transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
box/spout Version ^2.7 | — | — |
illuminate/support Version 5.3.* || 5.4.* || 5.5.* || 5.6.* || 5.7.* || 5.8.* || ^6.0 || ^7.0 | — | — |
illuminate/database Version 5.3.* || 5.4.* || 5.5.* || 5.6.* || 5.7.* || 5.8.* || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.