The package includes a clear README, repository tests, licensing, release notes, and a small dependency surface. Workflow checks also found a high-confidence bot-condition issue and all nine action references are unpinned.
45%
Total Score
50
100
88
67
The repository is owned by an individual account rather than an organization, so there is no visible organizational maintenance buffer. This makes the stalled activity more concerning, though ownership metadata alone is not a verdict.
Only two releases were published, with the latest in February 2023 and none in roughly three years and seven months. This strongly increases abandonment risk for a library dependency.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this is strong evidence that maintenance has stalled.
There are no new issues or merged pull requests in the last month, and two pull requests remain open. This supports the broader picture of limited recent project activity.
No security policy is present. This is a transparency gap for reporting vulnerabilities, though it is less severe for a small value-object library than for security-sensitive software.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/collections Version >=9.47 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.