Documentation, tests, licensing, and package identity are clear. Its lone maintainer and missing security policy add little support for adopting a release that has seen no updates since 2019.
40%
Total Score
67
100
72
88
The package has six releases, but its latest release was about seven years ago and it had no releases in the last 12 months. That long gap is strong evidence of abandonment risk.
One registry maintainer is consistent with a small user-owned project, but it also indicates limited publishing redundancy. Combined with the stale release history, this provides little maintenance resilience.
There are no open issues or pull requests and no activity in the last month. While that may reflect a small stable project, it provides no evidence of ongoing maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these counts provide no supporting evidence of an active user or contributor community.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a hygiene gap rather than a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.0,<5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.