Risky to adopt despite a recent stable release and a maintained-looking source repository. Packagist marks the package abandoned, and the repository currently has no commits or merged pull requests in the last three months; verify the replacement before depending on it.
30%
Total Score
50
100
78
80
Packagist marks the entire package abandoned and provides no replacement package, which is a serious adoption concern even though the source repository remains available.
The repository recorded zero commits and zero active maintainers over the last three months, which conflicts with the recent release and raises a meaningful maintenance-risk concern.
There were no new or closed issues or pull requests in the last month, while seven pull requests remain open; this suggests limited current project activity.
The repository name does not match the package name and its README does not mention the package, so the registry-to-source relationship is less transparent than expected.
Composer build tooling is present, but no security-scanning tool was detected; this is a transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0 | ^11.0 | ^12.0 | ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.