The README is substantial, the repository includes tests, and licensing is clear. Workflow references are not pinned, and no security policy is published.
66%
Total Score
67
88
67
The registry namespace and repository owner match, but the owner is an individual user rather than an organization. This supports package identity while leaving a limited backing structure.
The package is newly published, with one release and no established release cadence yet. That limits evidence of long-term maintenance.
One contributor made all two commits in the last three months, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-owned, so there is no shown organizational handoff buffer.
Composer build tooling is present, but no security scanning tooling was detected. For a new library, that is a modest transparency and maintenance gap rather than a severe risk.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for consumers and maintainers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/auth Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/queue Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.