The package includes a clear MIT license, usage documentation, repository tests, and no install-time scripts. Its small dependency footprint and matching source repository help, but security scanning is absent and the project has little activity evidence.
58%
Total Score
33
100
89
83
There were no commits and no active maintainers in the last three months, while the repository was last pushed in December 2018. This is the strongest evidence of abandonment risk.
The package and repository are both owned by the same individual account, providing consistent ownership context. Individual backing also means there is no organization-level maintainer capacity shown here.
Only one release exists, published in December 2018, with no releases in the last 12 months. This indicates a maturely aged but potentially abandoned package and materially lowers confidence in ongoing maintenance.
There are no open issues or pull requests, and no recent issue or pull-request activity. This is consistent with a quiet project but does not by itself distinguish resolution from abandonment.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanner is a hygiene gap, not evidence that the package is unsafe or unmaintained on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.