It has a clear license, tests, release notes, and a matching source repository. The single-maintainer project has no recent commits or security policy, so future fixes and oversight are less certain.
65%
Total Score
50
88
50
Only one registry maintainer is listed, which creates a limited publishing bus factor. The matching source repository provides some identity continuity but does not remove the dependency on one maintainer.
The package has 13 releases since March 2016, but none in the last 12 months and the latest release was published in August 2023. This indicates materially reduced release maintenance for the version being assessed.
The repository recorded zero commits and zero active maintainers in the last three months. That weakens evidence of ongoing maintenance and raises the chance that fixes may be slow or unavailable.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP library this is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving no documented route for reporting vulnerabilities or describing security handling. This is a transparency and response-readiness gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/session Version >=5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.