Risky to adopt: the package has had no release or repository activity for about three years, leaving maintenance and compatibility concerns. It is not deprecated or archived and has a clear license and documentation, but the long inactivity and tiny user base make it a liability for new projects.
44%
Total Score
25
100
72
75
The latest release was published about three years ago, and there have been no releases in the last 12 months. The 20-release history shows an initial burst of activity but no ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, after roughly three years since the last repository update. This indicates a strong abandonment risk for a package that provides authentication and admin functionality.
The repository is owned by an individual account rather than an organization, so the single registry maintainer reflects a narrow apparent project base. This reinforces the limited maintenance capacity suggested by the inactive repository.
The repository has zero stars and forks and only one watcher, offering little evidence of community use or review. Popularity is supporting evidence rather than a verdict, but it provides no compensating signal for the inactivity.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a maintenance and transparency gap, though it is secondary to the package's lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.