The package is compact, has a README and release notes, and uses only two runtime dependencies. Its repository is not archived, and it has no install-time scripts; the main remaining concern is limited evidence of long-term project maturity.
65%
Total Score
50
100
79
88
No license declaration, license file, or repository license file was detected, leaving the legal terms for using this dependency unclear.
The package is brand new, with all three releases published within about 43 minutes. This shows active initial work but provides no meaningful long-term maintenance history.
No commits or active maintainers were recorded in the last three months. Because the package itself is only hours old, this is limited evidence rather than proof of abandonment, but it leaves maintenance capacity unestablished.
Composer is used as the build tool, but no security scanning tool is configured. The missing scan is a modest transparency gap, not a severe dependency risk by itself.
The repository has no security policy. For a small date-conversion library this is a minor governance gap, but it provides no documented process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.