MIT licensing, tests, release notes, and a matching source repository provide useful transparency. The clean workflow audit and absence of install scripts help, but the project still has limited operating history and basic security-process coverage.
72%
Total Score
50
81
67
This is a very new package with two releases in less than a day. The quick initial release activity is not evidence of abandonment, but it provides little long-term maintenance history.
The repository records zero commits and zero active maintainers over the last three months. Because the package itself is only hours old and was recently pushed, this is limited evidence of inactivity rather than strong abandonment evidence, but the project remains lightly proven.
Composer build tooling is present, but no security scanning tools were detected. For a package exposing authenticated application endpoints and a write-capable tinker endpoint, that is a modest process gap.
The repository has no security policy. That reduces transparency for reporting vulnerabilities in a package that handles application data and exposes privileged operations.
Version v0.1.1 is not a stable major release, so compatibility and API maturity remain less established than for a stable release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psy/psysh Version ^0.12 | — | — |
illuminate/http Version ^12.0 | — | — |
illuminate/console Version ^12.0 | — | — |
illuminate/routing Version ^12.0 | — | — |
illuminate/support Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.