Long release gaps and a single registry maintainer reduce confidence in ongoing care. Clear licensing, tests, a matching repository, and a recent compatibility release provide useful reassurance.
70%
Total Score
50
86
100
One registry maintainer indicates a thin publishing base, increasing dependence on a single person. The linked repository and recent release show that publishing activity has not stopped.
The package has existed for over 10 years but only 8 releases, with a median interval of about 16 months and 1 release in the last year. Its latest release is recent, partly offsetting the slow cadence.
The repository had 0 commits and 0 active maintainers in the last 3 months, which weakens evidence of ongoing maintenance. A release was still published recently, so this is a caution rather than abandonment evidence.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest repository hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mockery/mockery Version ^1.3 | — | — |
illuminate/support Version 8.*|9.*|10.*|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.