Tests, a changelog, clear licensing, and a matching repository provide useful transparency. The one-person project has little external adoption and lacks a security policy; pin this version and monitor future releases.
65%
Total Score
50
100
94
50
Only one account has registry publish access, limiting publishing redundancy. The repository is user-owned rather than organization-backed, so there is no provided organizational context to offset that thin base.
The registry namespace and repository owner are different user accounts, and the repository owner is an individual rather than an organization. This does not prove a problem, but it offers limited visible backing for continuity.
The repository records zero commits and zero active maintainers in the last 3 months. Although the package is young and was recently pushed, the absence of recent commit activity raises maintenance risk.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these counts provide little evidence of broad review or community support.
No repository security policy was found. That weakens vulnerability-reporting transparency, though it is a hygiene concern rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^12.0|^13.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.