The package is clearly identified, licensed, and has a focused dependency set. Its limited testing and security documentation leave less evidence for long-term maintenance, so pinning this version is prudent.
58%
Total Score
50
75
50
The package includes a substantial README and release notes for version 1.0.2, which improves consumer transparency. The repository reports no tests or changelog, leaving less evidence of regression coverage, although the release notes partly compensate for the missing changelog.
Only three releases were published, all within roughly 1 hour, and none appeared in the last 12 months despite the package being about 15 months old. This is a meaningful maintenance concern, though the stable 1.0.2 release and recent repository push provide some counterweight.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reinforcing the long registry release gap. This suggests limited ongoing maintenance capacity.
The repository has 1 star, 0 forks, and 0 watchers, indicating little visible adoption or community backup. Popularity is supporting evidence only, so this modestly lowers confidence in project resilience rather than determining the verdict.
No repository security policy was found, so there is no documented channel or process for handling security reports. This is a transparency gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.