Usable with caveats: the release is well documented, tested, licensed, and backed by a matching active repository. However, it has only two releases and no commits or active maintainers in the last three months, so ongoing maintenance capacity is uncertain.
68%
Total Score
67
88
90
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, leaving less visible institutional backing for long-term continuity.
The package is about 404 days old but has only two releases, with one release in the last 12 months; this is limited evidence of sustained maintenance for a production-oriented Laravel library.
The repository recorded zero commits and zero active maintainers during the last three months. Although the current release is recent, the lack of recent development activity creates a meaningful maintenance and abandonment concern.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and maintenance gap rather than a severe risk.
Two workflows use read-only permissions, while the release workflow has top-level write permissions. Write access is understandable for publishing, but broad release permissions warrant some supply-chain caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.