The package is clearly licensed, stable, and linked to a matching repository. Its very small project has had no commits or releases for about 2 years and 6 months, and its workflow uses two unpinned actions.
58%
Total Score
50
83
50
The package has 13 releases but none in the last 12 months; the latest release was about 2 years and 6 months ago, indicating stalled maintenance.
There were no commits and no active maintainers in the last 3 months, consistent with the release gap and raising abandonment risk.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and maintenance gap for a library.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The sole workflow was fully analyzed with no high-confidence findings, but both of its action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.1 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.