Risky to adopt: this package has had no release or repository activity since September 2021, with only two releases and no users or forks. It is small and understandable, with a matching repository, tests, a README, and an MIT declaration, but its long inactivity makes maintenance uncertain.
43%
Total Score
50
100
64
75
The package is about five years old but has only two releases, both clustered on its first day, and none in the last 12 months. This strongly indicates abandonment risk despite the stable 1.0.1 version.
A single registry maintainer is consistent with a user-owned small project, but it provides little redundancy if that person stops maintaining it. The repository's matching ownership confirms accountability but not active maintenance.
The repository has zero stars and forks and only one watcher, offering no supporting evidence of community review or shared maintenance. Low popularity alone is not disqualifying, but it reinforces the inactivity concern.
Composer build tooling is present, but no security scanning tooling was found. For this small package this is a transparency gap rather than a severe risk, and the absence of workflows limits the practical significance.
The repository is not formally archived, which avoids the most severe abandonment signal, but its last push was about five years ago and does not offset the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 5.6.* | — | — |
illuminate/contracts Version 5.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.