The package is small and clearly documented, with tests and a source repository that matches the package. Its slow release cadence, no recent commit activity, and missing security policy leave maintenance and response capacity uncertain.
65%
Total Score
67
100
89
83
The repository is owned by the same individual as the registry namespace, so ownership is consistent and does not suggest an unrelated publishing account. Individual ownership also means the visible maintainer base is relatively narrow.
The package has five releases over about three and a half years, with two releases in the last 12 months, but the median interval is about 11 months. That is a slow maintenance cadence for a dependency.
There were zero commits and zero active maintainers in the last three months. Although the recent release shows the project can still publish, current development activity is limited.
The repository uses Composer and Make, but no security-scanning tooling was detected. For a small package this is a hygiene gap rather than a severe dependency risk.
The repository has no security policy. That makes reporting and handling future vulnerabilities less transparent, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.