It is clearly licensed, documented, and has a small dependency surface. The repository is straightforward to inspect, but there is no security policy or automated security scanning.
38%
Total Score
50
100
75
75
This package has had only one release, published about 10 years ago, with no releases in the last 12 months. That strongly suggests abandonment and leaves current compatibility unverified.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, there is no observed maintenance activity supporting continued use.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap for a package intended to run inside applications.
The repository is not archived, which preserves a basic path for maintenance, but its last push was about 10 years ago and this does not offset the lack of activity.
The repository has no published security policy. This reduces transparency for reporting and handling security issues, although it is a secondary concern compared with the long maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=5.0.0 | — | — |
illuminate/database Version >=5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.