The small, focused dependency set and explicit MIT license are positives. The pre-1.0 version and absent security policy leave little documented cushion for future maintenance.
42%
Total Score
0
50
50
The package has had four releases, but none in the last 12 months; its latest release was about 17 months ago. This indicates substantial abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and weakening confidence in ongoing maintenance.
The repository name matches the package, but its README does not mention this package and instead documents a different Composer package name. That raises concern about whether the linked source fully corresponds to this release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a documentation gap rather than evidence of a security incident.
Version v0.2.3 is not a stable major release, so the API may still change and the project shows limited maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=10.0 | — | — |
illuminate/database Version >=10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.