The source offers little validation or security-process evidence for future changes. Its small, focused implementation and MIT licensing are positives, but ongoing dependency risk remains high.
42%
Total Score
0
100
75
75
The latest release was published in September 2020, and there were no releases in the last 12 months. A two-release history over roughly six years gives little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and increasing abandonment risk.
The published artifact has no README, tests, or changelog; the missing tests and changelog are normal for an artifact, while the repository also reports no tests or changelog. The GitHub release for this version provides some release documentation evidence, though no notes were captured.
Composer is used as a build tool, but no security-scanning tools were detected. This is a maintenance and transparency gap, especially alongside the lack of recent development activity.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a modest transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~5.0|6.*|7.*|8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.