The package is clearly licensed and has a small, focused dependency set. Its minimal repository has no security policy and very little visible adoption, which leaves maintenance support uncertain.
43%
Total Score
100
58
83
The latest release was published nearly six years ago, with no releases in the last 12 months. This is strong evidence of stalled maintenance for a dependency.
The artifact has no README, which makes integration harder for a library consumers must understand. The absence of tests and a changelog in the published artifact is normal packaging practice and is not a concern by itself.
The repository has zero stars and forks and only two watchers, providing little evidence of an active user or contributor community. Popularity is supporting evidence, so this reinforces rather than determines the maintenance concern.
The repository is not archived, which is a compensating sign, but its last push was nearly six years ago and does not offset the stale release history.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though it is less severe than the prolonged lack of releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.8 | — | — |
illuminate/database Version ^5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.