The package is licensed and has no install-time scripts, reducing adoption friction and execution risk. Its small artifact is understandable, but there is little evidence of ongoing care or reliable project ownership.
42%
Total Score
0
71
100
There has been only one release, v0.0.1, published about 2 years and 11 months ago, with no releases in the last 12 months. This is strong evidence of an immature or abandoned dependency.
The repository had zero commits and zero active maintainers in the last 3 months. Combined with the old sole release, this indicates no observed ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. That raises a genuine concern that the linked project may not clearly establish ownership of this package.
The assessed release is v0.0.1 and is not a stable major release, so the public API may still change substantially. The lack of later releases provides no evidence that this early version matured.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.