The package has a clear MIT license, tests, a substantial README, and no install-time scripts. Its single-maintainer model, absent security policy, and no commits in the last three months leave less maintenance depth than mature alternatives.
68%
Total Score
50
100
88
75
Only one registry maintainer is listed, which creates limited publishing redundancy; the linked repository is user-owned, so there is no organization backing to offset that concern.
The registry namespace and repository are owned by the same individual, and the project is explicitly user-backed rather than organization-backed; this is consistent but offers limited institutional continuity.
The package has existed for about 10 years with 15 releases, but only one release in the last 12 months and a median interval of about 281 days indicate a slow maintenance cadence.
There were no commits and no active maintainers in the last three months, a concrete sign of limited recent development capacity despite the recent push and release history.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~5|~6|~7|~8|~9|~10|~11|~12|~13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.