Usable with caveats: the package is established, licensed, stable, and its repository is active and correctly linked. However, it has had no commits in the last three months, only one release in the last year, and no security policy or automated security scanning.
65%
Total Score
50
100
83
75
The published artifact lacks a README, but that is a consumer-documentation gap for a Laravel library; a GitHub release with notes for this version provides some release transparency. The absence of packaged tests and a changelog is normal for published artifacts and is not treated as a defect here.
The registry namespace and repository owner match, and the repository is owned by the same individual rather than an organization; this is consistent ownership but offers a limited institutional backing signal.
The package has existed for over 10 years with 100 releases, but only one release was published in the last year, indicating a currently slow release cadence.
No commits were recorded in the last three months and no maintainers were active during that period, which raises a meaningful concern about ongoing maintenance despite the recent release push.
The repository uses Composer, but it reports no security-scanning tools, leaving automated detection of dependency or code issues less evident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.