Strong documentation, tests, licensing, and a recent repository push support adoption. The small maintainer base, sparse release history, missing security policy, and unpinned workflow actions warrant monitoring for long-term upkeep.
66%
Total Score
50
81
50
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor concentration is not offset by visible organizational backing.
The package has only two releases over 454 days, with one release in the last 12 months and a median interval of about 380 days, indicating a slow maintenance cadence.
All recent commit activity comes from one contributor, creating a high dependency on that person's continued availability.
Only one commit was recorded in the last three months from one active maintainer, showing limited recent development activity despite the recent repository push.
Composer build tooling is present, but no security-scanning tooling was detected, leaving automated checks for dependency or code risks unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.