The package has a clear MIT license, a matching repository, tests, and a documented release. Its single-maintainer project has no security policy, and development has been inactive for over two years, so future fixes are uncertain.
62%
Total Score
67
100
88
88
Only one registry maintainer is listed. That is consistent with the repository being user-owned, but it leaves limited visible publishing capacity when combined with inactive development.
The package has six releases since September 2021, but none in the last 12 months and the latest release was over two years ago. This weakens confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with more than two years since the last push and indicating probable abandonment risk.
The repository uses Composer, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.