It remains a small, clearly documented MIT package with repository tests and no install scripts. The beta-only history and absent security scanning leave little evidence of ongoing support. Its README, tests, and license make the old code easier to assess, but not safer to adopt.
40%
Total Score
50
71
83
The latest release was published nearly seven years ago, and there have been no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having seven releases overall.
There were no commits and no active maintainers in the last three months, consistent with the nearly seven-year release gap. This materially increases the risk that compatibility or security issues will go unanswered.
Composer build tooling is present, but no security scanning tools were detected. For an old package with no recent activity, that leaves an important maintenance and vulnerability-monitoring gap.
The repository has no formal security policy. The README provides a security contact, which helps transparency, but it does not establish a documented vulnerability-handling process.
The assessed release is v0.0.7-beta, the latest version, and all recent releases are prereleases. That leaves the public API and maintenance commitment less certain.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 6.*|5.8.*|5.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.