The MIT declaration conflicts with the Apache-2.0 license file, and the repository has no security policy or scanning. A real README, tests, changelog, and matching repository provide useful transparency.
58%
Total Score
50
100
78
75
The artifact contains a license file and the repository also has one, but the manifest declares MIT while the detected file is Apache-2.0; that mismatch needs clarification before adoption.
The package is backed by a matching individual-owned repository rather than an organization, so the single registry maintainer reflects a thin ownership base.
This package has only one release, published about five months ago, so there is little release history to demonstrate sustained maintenance.
There were no commits and no active maintainers in the past three months, which is concerning for a package with only one release and limited evidence of ongoing support.
There are no open issues or pull requests and no recent issue or pull-request activity; combined with the lack of commits, this offers little evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.