The source includes tests, a changelog, a matching README, and an MIT license. It is not archived or deprecated, but the lone maintainer and lack of security scanning provide little evidence of ongoing support.
45%
Total Score
25
75
50
The latest release was published about seven years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
The repository has had no commits or active maintainers in the last three months, and its last push was about six years ago. The stable codebase provides no compensating evidence of current support.
The registry lists one maintainer, which creates a thin support base. This is more concerning alongside the long release and commit gap, and the project is user-backed rather than organization-backed.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not evidence that the release is unsafe by itself.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, although it does not outweigh the much stronger maintenance evidence alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.24 | — | — |
illuminate/support Version 5.8.*|^6.0 | — | — |
illuminate/database Version 5.8.*|^6.0 | — | — |
illuminate/container Version 5.8.*|^6.0 | — | — |
illuminate/contracts Version 5.8.*|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.