The four-file package is simple to inspect, but it lacks a security policy for reporting vulnerabilities. Its proprietary licensing also creates a significant reuse constraint for an open-source dependency.
35%
Total Score
0
58
50
The package has had no releases in the last 12 months, and its latest release was in October 2020 despite being over five years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The manifest declares a proprietary license and no license file was found. That is a real reuse and transparency constraint for a package presented as open source.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of active adoption or review.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a modest hygiene gap alongside the absence of a security policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 5.6.* | — | — |
kreait/firebase-php Version 4.43 | — | — |
illuminate/contracts Version 5.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.