The package includes tests, documentation, and an MIT license, with no install-time scripts or deprecation notice. Its lone release and inactive repository make long-term compatibility and support uncertain.
38%
Total Score
25
71
75
This is the only release, published over 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency.
The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and indicating no current maintenance.
A single registry maintainer provides little publishing redundancy. The repository is user-owned rather than organization-backed, so there is no provided backing signal to compensate for that thin base.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest supply-chain hygiene gap, not evidence that the release is malicious.
The repository is not archived, which is a positive, but its last push was in August 2016 and does not offset the evidence of prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 5.2.* | — | — |
elasticsearch/elasticsearch Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.