The MIT license, readable documentation, and changelog make the package easy to inspect and adopt. The absence of security scanning adds a smaller maintenance concern. Its limited project activity leaves compatibility work to the adopting team.
38%
Total Score
0
75
50
The package has only one release, published in January 2020, with no releases in the last 12 months. This is strong evidence that maintenance has stopped and materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release history showing no activity since January 2020.
The repository uses Composer for its build and dependency workflow, but no security scanning tools were detected. Composer support is appropriate; the missing scanning is a modest hygiene gap.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a secondary transparency and maintenance concern rather than a standalone reason to reject the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^5.8|^6.0 | — | — |
illuminate/session Version ^5.8|^6.0 | — | — |
illuminate/support Version ^5.8|^6.0 | — | — |
illuminate/contracts Version ^5.8|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.