The package includes a README, tests, a matching source tree, and a declared MIT license. Its workflow audit found no dangerous patterns, but the very small project footprint and missing security policy leave little evidence of ongoing support.
42%
Total Score
25
100
78
50
The package has had only three releases, with none in nearly six years; the latest registry release was in October 2020. This is strong evidence that maintenance has stopped.
There were no commits and no active maintainers during the last three months, consistent with the repository's last push nearly six years ago. This substantially increases abandonment risk.
The repository is owned by an individual rather than an organization, so there is no provided evidence of organizational support to compensate for the inactive history.
The repository has only 3 stars and 1 fork, providing little external evidence of adoption or community support. Popularity is supporting evidence, so this is a modest concern rather than a decisive risk.
The project uses Composer, but no security scanning tools were detected. For a small PHP library this is a hygiene gap, though it is less significant than the maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ^8.0 | — | — |
illuminate/database Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.