The repository includes a substantial test suite, a GitHub release, and clear MIT licensing. Its lack of security scanning and the single-maintainer publishing setup add little reassurance for a package with no ongoing activity.
38%
Total Score
50
100
72
75
This is the package's only release, published over six years ago, with no releases in the last 12 months. That gives strong evidence of abandonment risk for a dependency taken today.
Only one registry account has publish access. A small publisher list is not inherently unhealthy, but with only one historical release and no recent activity it offers little visible publishing resilience.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide no meaningful community backing for an otherwise inactive project.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling is present. That weakens ongoing assurance while the project is already inactive.
The repository is not archived, which avoids the most severe abandonment signal, but its last push was over six years ago. The repository remains available without showing current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^8.0 | — | — |
illuminate/database Version ^8.0 | — | — |
illuminate/container Version ^8.0 | — | — |
illuminate/contracts Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.