Its MIT license, tiny dependency set, and clear README reduce adoption friction. There is no security policy, and recent repository activity is limited to one contributor despite a fresh release.
72%
Total Score
50
100
93
50
The package has existed for about 4 years and has 15 releases, with its latest release published recently. Only one release appeared in the last 12 months, indicating modest rather than vigorous release activity.
All commits in the last three months came from one contributor, creating a meaningful single-maintainer continuity risk. The linked repository is user-owned rather than organization-backed, so no organizational handoff evidence compensates for that concentration.
The repository was pushed on the latest release date and had one commit in the last three months, showing current maintenance but a very low activity level.
The repository has no security policy, leaving no documented channel or process for handling vulnerabilities. The README does provide an email contact, which partially offsets the documentation gap but does not replace a policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=5.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.