Clear documentation, tests, a changelog, and a security policy support practical adoption. Maintenance evidence is limited because this is a one-release package with no commits in the last three months, so pinning this version carries some continuity risk.
65%
Total Score
50
100
88
88
The package and repository are owned by the same individual account. This is coherent ownership, but it also indicates a single-person project with limited visible organizational backing.
The package has made one release, first published about 10 months ago, with no subsequent release activity. This limits evidence of continued maintenance.
There were no commits and no active maintainers in the last three months. For a package released only once, this leaves maintenance responsiveness and continuity unproven.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanner is a modest hygiene gap rather than evidence of abandonment.
No GitHub Actions workflows were present to audit, so there are no detected workflow hazards, but this also provides no automation evidence for testing or publishing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^3.0 | — | — |
illuminate/support Version ^11.0|^12.0 | — | — |
illuminate/filesystem Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.