The package includes a clear README, tests, an MIT license, and a repository that matches its name. Organization backing and a non-archived repository provide useful continuity, but the project offers little independent security or adoption evidence.
46%
Total Score
50
71
50
The latest release was published in January 2020, with no releases in the last 12 months. This long release gap is strong evidence of abandonment risk for a maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing more than six years without a new release.
The repository has 7 stars and 2 forks, so there is limited external adoption evidence. Popularity is supporting evidence only and does not by itself make the package unsafe.
The project uses Composer build tooling, but no security-scanning tool was detected. This is a modest transparency gap, not a severe supply-chain concern on its own.
No repository security policy was found, reducing the project's documented vulnerability-reporting transparency. This matters, but it is secondary to the prolonged maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.1 | — | — |
illuminate/http Version >=5.0 | — | — |
illuminate/support Version >=5.0 | — | — |
illuminate/database Version >=5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.