The repository is small and has no security policy, while all nine workflow actions are unpinned. MIT licensing, documentation, tests, and a changelog provide useful transparency, but they do not offset the prolonged inactivity.
45%
Total Score
25
72
50
The package has had only one release, v0.1.0, published 769 days ago, with no releases in the last 12 months. This is strong evidence of limited maintenance for a young package.
There were zero commits and zero active maintainers in the last three months, consistent with the single-release history and indicating effectively inactive development.
The package uses a post-autoload-dump install lifecycle script. This warrants attention because installation executes package-defined behavior, although the signal alone does not show that it is unsafe.
The repository is owned by an individual user rather than an organization, so the single registry maintainer reflects a genuinely thin project backing.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little external evidence of maturity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^10.0||^11.0 | — | — |
illuminate/support Version ^10.0||^11.0 | — | — |
illuminate/contracts Version ^10.0||^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.