The package includes tests, a substantial README, and matching MIT licensing. Install-time scripts and the lack of a repository security policy add modest maintenance and transparency concerns.
58%
Total Score
50
79
50
post-install-cmd and post-update-cmd scripts run during Composer operations, increasing install-time behavior and review surface. This is a modest supply-chain hygiene concern rather than evidence of abandonment.
Only one registry account has publish access. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to compensate for the thin publishing base.
Five releases arrived within roughly 10 days, with a median interval of about 12 hours, but no newer release has appeared in roughly 10 months. The early burst followed by a long pause suggests uncertain ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. For a package less than a year old, that is meaningful evidence of stalled maintenance, though it does not by itself prove abandonment.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning coverage is a transparency and hygiene gap, not a verdict on the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^10.0 | ^11.0 | ^12.0 | — | — |
illuminate/console Version ^10.0 | ^11.0 | ^12.0 | — | — |
illuminate/routing Version ^10.0 | ^11.0 | ^12.0 | — | — |
illuminate/support Version ^10.0 | ^11.0 | ^12.0 | — | — |
illuminate/filesystem Version ^10.0 | ^11.0 | ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.