The package includes a clear README, release notes, an MIT license, repository tests, and a small focused dependency set. Its workflow uses unpinned actions and the project has no security policy, so ongoing maintenance and build hygiene remain unproven.
68%
Total Score
75
100
86
67
This is the first release, published today, so there is no release track record or established cadence yet. That limits confidence in long-term maintenance but does not by itself indicate abandonment.
There were no commits or active maintainers in the last three months, but the package itself was released today, making the absence of historical activity primarily a maturity gap rather than evidence of a collapsed project.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest repository hygiene gap, not a standalone dependency risk.
The repository has no security policy. For a new package this reduces disclosure transparency, though it is not evidence that the release is unsafe.
The single workflow was fully analyzed with no reported audit findings or untrusted-code sinks. Both action references are unpinned, which leaves build inputs less reproducible and is a minor supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/container Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.