The codebase is tiny and has no tests or security policy. It is MIT-licensed, has no install scripts, and matches its repository, but its single-maintainer footprint leaves little visible support.
42%
Total Score
50
100
72
75
This is the package's only release, published more than 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the stable version label.
Only one registry account has publish access. This is a thin publishing footprint and provides little redundancy, although registry access does not itself prove maintenance activity.
The repository owner is identified as a user account rather than an organization, so the available backing signal does not show organizational maintenance capacity.
There are no open issues or pull requests and no recent activity. While zero backlog is not inherently negative, it provides no evidence of an active maintenance community alongside the old release history.
The repository has zero stars and forks and only one watcher, offering almost no supporting evidence of community adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/session Version 5.1.* | — | — |
illuminate/support Version 5.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.