The MIT license, documented release notes, tests in the repository, and matching source repository are positives. Its release history and recent commit activity show a long-maintained gap, while the name resemblance creates an avoidable adoption risk.
38%
Total Score
75
100
69
83
The package is reported to borrow the identity of the much more established spatie/backtrace, with 6,098,011 monthly downloads versus none for this package. Although artifact overlap is zero and the README does not identify it as the lookalike, the identity signal remains a serious adoption risk.
The latest registry release was in December 2016, nearly nine years ago, with no releases in the last 12 months. That is strong evidence of an aging dependency even though it has nine total releases.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the stale registry release history, this points to limited current maintenance capacity.
The repository uses Composer for builds, but no security scanning tools were detected. The missing scanning is a modest hygiene gap, not a standalone dependency blocker.
No repository security policy was found. This reduces transparency for reporting and handling vulnerabilities, particularly for a dependency with no recent release activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/session Version ~5.1.0|~5.2.0|~5.3.0 | — | — |
illuminate/support Version ~5.1.0|~5.2.0|~5.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.