Documentation, tests, and a clear package layout make the release straightforward to evaluate. However, it has not received a follow-up release or commit in about six months, so ongoing maintenance remains uncertain.
61%
Total Score
25
100
89
75
There were no commits and no active maintainers in the last three months, despite the package being only about six months old. That is the clearest evidence that ongoing maintenance is uncertain.
The registry namespace and repository belong to the same individual account, so ownership is consistent. Individual ownership does not provide the redundancy of an organization-backed project.
This is a young package with one release, made about six months ago. The lack of release history limits evidence of continued maintenance, though its age partly explains the small record.
The repository has no stars, forks, or watchers. For a newly released package this is weak supporting evidence, but it is not decisive by itself.
The repository has no security policy. This is a modest transparency gap for a package that handles API keys, although the available scanning tooling partly offsets it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/cache Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.