Usable with caveats: it has clear documentation, tests, a matching source repository, and a permissive license, but it is an early-alpha project whose activity stopped about 11 weeks ago after a rapid initial release burst. Treat it as experimental and verify that maintenance resumes before making it a core dependency.
62%
Total Score
50
86
50
The package and repository are owned by the same individual account, so the source clearly backs the package. However, there is no organizational backing to compensate for a potentially thin maintainer base.
The package is only about 103 days old, with seven releases concentrated in its first 25 days. This shows an active initial push but limited evidence of sustained maintenance.
There were no commits and no active maintainers in the last three months; with the latest release and repository push about 11 weeks ago, this is a meaningful sign that maintenance may have stalled.
No security policy was found, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, though it is less severe because the repository has no analyzed workflows and does not by itself indicate abandonment.
Version 0.9 is not a stable major release, and the README explicitly describes the project as early alpha. That is an important maturity risk for a package providing broad orchestration functionality.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version >=10.0 | — | — |
illuminate/support Version >=10.0 | — | — |
illuminate/contracts Version >=10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.