Usable with caveats: it is a young package with active recent development and thorough tests, but all repository work comes from one contributor and there is no security policy or scanning. Review ownership and security practices before relying on it for sensitive provisioning workflows.
65%
Total Score
70
100
78
90
Only one registry account has publish access. This is a limited publishing base, though registry access alone does not establish who actively maintains the code.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This confirms alignment without providing organizational maintenance depth.
The package is only 27 days old, despite 12 releases and 11 releases in the last 12 months. This shows active iteration but provides little long-term maintenance evidence.
One contributor made all 12 commits in the last 3 months, creating a clear single-person continuity risk. The repository is user-owned rather than organization-backed, so there is no provided organizational evidence to offset that concentration.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but this offers no external adoption signal for a package that is only 27 days old.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/database Version ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.