The repository contains a real test suite, uses Composer, and matches the package name, which supports basic project maturity. One registry maintainer and limited repository activity leave long-term maintenance uncertain.
60%
Total Score
50
100
88
83
Only one registry account has publish access. That is a limited publishing base and creates some continuity risk, although it does not by itself show that repository maintenance is inactive.
The package has four releases, but none in the last 12 months; its latest release was about 2 years and 6 months ago. This indicates a stalled release cadence and lowers confidence in ongoing maintenance.
There were no commits and no active maintainers during the last 3 months, consistent with the last push being about 2 years and 6 months ago. This is the clearest sign of stalled maintenance.
The repository uses Composer build tooling, but no security scanning tool was detected. The build setup is present; the missing scanner is a minor hygiene gap rather than evidence of abandonment.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations. This is a secondary concern because the package is not showing a direct security finding here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^7.0|^8.0|^9.0|^10.0|^11.0 | — | — |
illuminate/validation Version ^7.0|^8.0|^9.0|^10.0|^11.0 | — | — |
illuminate/translation Version ^7.0|^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.