This release appears generally healthy and reasonable to depend on: it is not deprecated or archived, has an organization-owned repository with recent activity, a substantial test suite, clear documentation, a license file, and a modest runtime dependency footprint. The package is still young at 28 days old, and all 31 recent commits come from one contributor, which creates a meaningful continuity risk despite the organization backing. Missing security scanning and a repository security policy are additional hygiene gaps, but the repository has safe workflow findings and the package shows strong early maintenance activity.
78%
Total Score
90
100
88
80
The package is very young at 28 days old, which limits evidence of long-term durability, but 13 releases in that period show active iteration rather than abandonment.
One contributor produced all 31 commits in the last three months, creating a genuine single-maintainer continuity risk; organization ownership provides some ability to hand maintenance off but does not eliminate the concentration.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap that lowers confidence without independently indicating abandonment.
No repository security policy was found, reducing transparency around vulnerability reporting and response expectations.
The repository's sole workflow lacks top-level token permissions. Although no write permissions were explicitly declared, explicit least-privilege configuration would provide stronger CI hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^13|^12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.