Testing, documentation, and licensing are in place, while the single-maintainer project has no security policy. The workflow audit found no dangerous patterns, but all four actions are unpinned.
58%
Total Score
33
100
83
75
The repository recorded zero commits and zero active maintainers in the last three months, consistent with no observed activity for about 13 months and increasing abandonment risk.
Only one registry maintainer is listed. That is consistent with the user-owned repository, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.
The registry namespace and repository are owned by the same individual account, so the package has direct ownership alignment but no organizational backing shown by this signal.
The package has only two releases, both published about 15 minutes apart, and no releases in the last 12 months despite being about 13 months old. This suggests limited release maturity and ongoing maintenance evidence.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but this offers no external adoption signal to offset the thin maintenance history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0 || ^12.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.