Tests and a real source tree provide useful confidence, while the minimal README and absent security policy make adoption less transparent. The package has a modest dependency footprint and no deprecation notice.
55%
Total Score
50
100
79
50
A post-autoload-dump Composer script runs during installation. This is not inherently unhealthy, but it adds install-time behavior that should be understood before depending on the package.
Only one registry account has publish access. The linked repository is also user-owned, so there is no visible organization-backed maintainer base to compensate for that narrow publishing capacity.
The artifact includes tests and the repository also has tests, which supports basic project maturity. Its 15-character README only says “In development,” leaving library consumers with little documentation.
The package has 23 releases over roughly seven years, but none in the last 12 months and the latest release was over two years ago. The historical cadence is established, but current maintenance appears stalled.
There were no commits and no active maintainers in the last three months, consistent with the repository having received no push for over two years. This is a clear abandonment concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^9.0|^10.0|^11.0 | — | — |
illuminate/routing Version ^9.0|^10.0|^11.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0 | — | — |
illuminate/database Version ^9.0|^10.0|^11.0 | — | — |
illuminate/contracts Version ^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.