Compatibility and ownership are the main remaining questions. The package is clearly documented and licensed, but nearly eight years without a release or repository activity makes future fixes unlikely.
45%
Total Score
50
92
75
Only one registry publishing maintainer is listed, and the project is user-owned rather than organization-backed, leaving limited visible publishing capacity.
The package has had no release in nearly eight years and none in the last 12 months, which strongly raises abandonment risk despite its five-release history.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance to offset the stale release history.
The linked repository has no security policy, reducing transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ~5.6 | — | — |
illuminate/support Version ~5.6 | — | — |
illuminate/contracts Version ~5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.