Usable with caveats: the package is mature, licensed, tested, and clearly backed by its source repository, but it has had no release or commit activity for over three years. Treat it as stable legacy code and verify compatibility before adopting it.
58%
Total Score
33
100
83
90
The repository recorded zero commits and zero active maintainers in the last three months, strongly indicating that ongoing maintenance has stopped.
The repository is owned by an individual account rather than an organization, so the two registry maintainers do not provide evidence of broader organizational maintenance capacity.
The package has 34 releases over roughly 12 years, but none in the last three years and seven months; this is a meaningful maintenance concern for a dependency.
There were no new or closed issues and no merged pull requests in the last month, consistent with an inactive project and increasing maintenance uncertainty.
Composer is used for builds, but no security scanning tools are configured; this is a transparency and assurance gap, partly tempered by the package's established tests and long release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pragmarx/support Version >=0.8.0 | — | — |
illuminate/support Version >=5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.