The package has a clear README, an MIT declaration, a matching organization repository, and a small runtime dependency set. Its maintenance evidence is weak, leaving a notable risk that fixes and compatibility updates will not arrive.
44%
Total Score
75
100
69
83
The package has 13 releases, but none in the last 12 months and its latest release was over two years ago. This is strong evidence of abandonment risk despite its earlier release activity.
The repository had zero commits and zero active maintainers in the measured three-month period. Combined with the stale release history, this materially raises abandonment risk.
The repository has zero stars, forks, and watchers, providing no supporting evidence of a broad user or contributor base. Popularity is only supporting evidence, so this is a minor concern rather than a verdict.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk on its own.
The linked repository is not archived, but its last push was over two years ago; the absence of archival status does not offset the stale activity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ~11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.