Risky to adopt: this package has had only one release, with no commits or releases since August 2018. It is licensed, documented, and not deprecated or archived, but its long-standing inactivity makes compatibility and maintenance a significant liability.
40%
Total Score
25
79
83
The package has only one release, and its latest release was over 8 years ago, with no releases in the last 12 months. This is strong evidence of an unmaintained dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's prolonged lack of releases. No provided signal shows current maintenance activity to compensate.
Only one registry account has publish access, leaving a thin publishing base. The matching user-owned repository provides some continuity, but no recent activity demonstrates an active maintainer team.
Composer is used for the build, but no security scanning tools are present. This is a modest transparency gap, though the absence of workflows limits the practical impact.
The repository has no security policy, reducing guidance for reporting and handling vulnerabilities. This adds a maintenance and transparency concern but is not by itself evidence that the package is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 5.5.* || 5.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.