The project has a long release history, a clear MIT license, tests in the repository, and a current stable release. Recent repository activity is absent, and CI has a high-confidence unpinned-image finding; its single maintainer and missing security policy add modest concern.
60%
Total Score
50
86
50
One registry maintainer is listed, and the repository is user-owned rather than organization-backed. That leaves limited visible maintainer redundancy if the primary maintainer becomes unavailable.
The package is mature, with 93 releases over about 9 years, but only one release in the last 12 months despite a historical median interval of about 10 days. This suggests a substantial slowdown.
There were zero commits and zero active maintainers in the last 3 months. Although the release was recently pushed, the absence of ongoing commit activity raises maintenance and abandonment concern.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest maintenance and vulnerability-management gap rather than a severe risk.
The repository has no security policy. This limits transparency about vulnerability reporting and response, though it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
hekmatinasser/jalali Version ^8.2.3 | — | — |
illuminate/validation Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.