Risky to adopt for new projects: the package has had no registry release in about 10 years and no repository commits in about 7 years. It is not deprecated or archived, and it has a matching repository, license, README, and release notes, but the long inactivity makes future compatibility and support uncertain.
43%
Total Score
0
50
75
83
The latest release was published about 10 years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained, despite its earlier release cadence.
The repository has had zero commits and zero active maintainers in the last 3 months, and its last push was about 7 years ago. That prolonged inactivity creates substantial abandonment and compatibility risk.
The package has only three declared runtime dependencies, but including fabpot/php-cs-fixer as a runtime dependency is unusual for a generator package and suggests some dependency hygiene concern.
Composer is used as the build tool, but no security scanning tools are present. This is a transparency gap, though it is secondary to the much more significant maintenance inactivity.
The linked repository is not archived, which is a compensating signal, but its last push was about 7 years ago and does not offset the observed lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.1|^5.2 | — | — |
fabpot/php-cs-fixer Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.