The package is clearly licensed, documented, and has a matching source tree. Its stable version and simple install setup do not offset the lack of current project support.
15%
Total Score
56
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because future maintenance and support are not indicated.
The package has 24 releases but none in the last 12 months; its latest release was about four years ago. Earlier regular releases show past activity but do not compensate for the prolonged halt.
The linked source repository is archived and was last pushed about four years ago. An archived upstream is a severe abandonment risk for a dependency.
Composer is used for builds, but no security-scanning tooling is reported. This is a modest hygiene gap rather than a standalone reason to reject the package.
The repository has no security policy. That is a transparency and reporting gap, although the package's abandonment and deprecation are more significant concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^7.0|^8.0|^9.0 | — | — |
smi2/phpclickhouse Version ^1.4.2 | — | — |
illuminate/database Version ^7.0|^8.0|^9.0 | — | — |
the-tinderbox/clickhouse-builder Version ^5.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.