Usable with caveats: the package is clearly structured, licensed, documented, and actively released, but it is only 49 days old and all recent repository work comes from one maintainer. The lack of security scanning and a security policy adds transparency risk for an integration handling OAuth and webhooks.
68%
Total Score
50
100
83
88
The package and repository are both owned by the same user account, and the repository is not archived. This supports package identity, but it does not provide the redundancy of organization-backed maintenance.
The package is only 49 days old and has eight releases, with releases arriving in a tight burst of roughly 1 hour 25 minutes at the median. That shows active early development but not yet a long maintenance record.
One contributor made all 14 recent commits, creating a concentrated maintenance dependency. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this concentration.
There were 14 commits in the last three months, showing recent activity, but all activity came from one maintainer.
The repository has zero stars, forks, and watchers. Given the package's age, this is weak supporting evidence rather than a standalone adoption risk, but it provides no external maturity signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^13.0 | — | — |
illuminate/routing Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.