It has a matching source repository, an MIT license, and a usable README. No security policy or automated security scanning adds transparency and upkeep concerns.
38%
Total Score
25
50
50
The package has made no releases in more than seven years, with zero releases in the last 12 months. Its 96 historical releases show prior activity but do not offset the prolonged halt.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent registry releases and indicating a serious abandonment risk.
There were no new or closed issues or pull requests in the last month, and no pull requests were merged. This reinforces the lack of current project activity, although the open-issues count is unknown.
Composer is used for the build, but no security-scanning tool was detected. That leaves dependency and vulnerability checks less visible than they would be in an actively maintained project.
The linked repository has no security policy. This is a transparency and maintenance gap for a library, though it does not by itself show that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version 5.* | — | — |
illuminate/support Version 5.* | — | — |
balping/json-raw-encoder Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.