Recent releases, tests, release notes, and security scanning support continued development. One contributor carries all recent commits, and no security policy is published, leaving limited maintenance redundancy and disclosure guidance.
64%
Total Score
50
88
75
The manifest declares MIT, while the artifact license file is detected as Apache-2.0; although a license file exists, the mismatch creates genuine adoption and compliance uncertainty.
One contributor made 100% of the recent commits, so a maintainer departure would leave no demonstrated handoff capacity.
Five commits in the last 3 months show recent activity, but all came from one active maintainer, limiting evidence of durable maintenance capacity.
No repository security policy was found, so users have no documented vulnerability-reporting path; the presence of Sonar scanning helps but does not replace disclosure guidance.
Version 0.4.2 is not a stable major release, but it is not marked prerelease and recent releases contain documented changes, making this a modest maturity concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^5.8|^6.0|^7.0|^8.0 | — | — |
illuminate/support Version ^5.8|^6.0|^7.0|^8.0 | — | — |
illuminate/database Version ^5.8|^6.0|^7.0|^8.0 | — | — |
illuminate/filesystem Version ^5.8|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.