The small codebase has clear packaging, licensing, and release notes, but limited evidence of ongoing engineering support. Its organization backing helps offset the single registry maintainer and modest repository activity.
58%
Total Score
50
100
75
75
The package has had no release in nearly three years, with eight releases overall and none in the last 12 months. This is the strongest sign that maintenance may have stopped.
There were no commits or active maintainers in the last three months, consistent with a project whose development has effectively paused.
There were no recent issues or pull requests, and no open work is visible. This is compatible with a tiny stable package but provides little evidence of active support.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, though not severe for this small package.
The linked repository is not archived, but its last push was nearly three years ago, so the non-archived status does not demonstrate active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
illuminate/filesystem Version ^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.