The package is clearly licensed, internally consistent, and backed by an organization with a matching repository. Its releases and commits stopped in January 2022, so ongoing maintenance and compatibility support are uncertain.
43%
Total Score
75
100
83
75
The package has had no release in more than four years despite 14 releases concentrated on January 13, 2022. This is strong evidence of abandonment risk, although the package is not deprecated.
There were no commits and no active maintainers in the repository during the measured three-month period. Combined with the multi-year release gap, this materially raises abandonment risk.
The repository has zero stars and zero watchers, with only one fork. Popularity is supporting evidence rather than a verdict, but these numbers provide little external evidence of active community use.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are present. The missing scanning is a hygiene weakness rather than a standalone dependency blocker.
The repository has no security policy. This reduces transparency about vulnerability reporting, though it is less significant than the prolonged lack of release and commit activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ~8.0 | — | — |
illuminate/config Version ~8.0 | — | — |
composer/installers Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.