It is licensed, documented, and has no install-time scripts. The one-person project has no recent release activity or security policy, so future compatibility and fixes are unlikely.
22%
Total Score
50
60
75
The package includes a substantial README, but it explicitly says the author no longer maintains the project and recommends swapping it out. A GitHub release exists for this version, but that does not offset the stated abandonment.
There has been only one release, published nearly six years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility or security fixes.
There are no open issues or pull requests and no recent issue or pull-request activity. In combination with the single old release, this provides no evidence of active support.
The repository has no security policy, leaving no documented path for reporting or coordinating security issues. This compounds the maintenance concern, especially for a package that handles archive files.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=5.0 | — | — |
illuminate/filesystem Version >=5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.