The package has had no release or repository activity for more than eight years, and its sole maintainer and very small project footprint limit confidence in future fixes. It is licensed, documented, tested, non-deprecated, and has no install-time scripts, so the risk is mainly abandonment rather than opaque packaging.
55%
Total Score
33
100
83
83
This is a 3,091-day-old package with only one release and no releases in the last 12 months, which is a substantial maintenance concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no observed ongoing maintenance.
One registry maintainer is consistent with a small user-owned project, but it leaves little visible publishing capacity if that maintainer becomes unavailable.
The registry namespace and repository are owned by the same individual account, showing direct ownership but no organization-level backing.
The repository has 2 stars and 1 fork, providing little evidence of a broad community that could help sustain or review the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.