The package has a small, clear artifact and no install-time scripts. Its sole release was in March 2017, the repository has not been pushed since then, no license is present, and the repository does not identify this package.
28%
Total Score
50
75
This package has only one release, published in March 2017, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
Neither the package nor the linked repository declares or contains a recognized license. That leaves the legal terms for adopting the code unclear.
The linked repository name does not match the package name and its README does not mention the package. This raises a concrete concern that the repository may not be the package's source.
The repository is not archived, which is a small positive, but its last push was in March 2017 and does not offset the absence of subsequent release activity.
The linked repository has no security policy. For a small, inactive package this adds a transparency gap, although it is less significant than the lack of maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rollbar/rollbar Version ~0.11 | — | — |
illuminate/support Version 4.*|5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.