Its MIT license, detailed README, release notes, tests, and organization backing improve transparency. Workflow dependencies are unpinned and the repository has no security policy, so pin this exact version and monitor early changes.
67%
Total Score
75
79
50
The package was first released within hours of the latest release and has only two releases, so there is not yet evidence of a sustained release track. The linked repository was pushed recently, which fits a genuinely new project but does not establish maturity.
There are no commits or active maintainers recorded over the last three months, which leaves maintenance capacity unproven. The repository was created or updated recently and has two merged pull requests, partly explaining the short history.
The repository uses Composer, but no security scanning tools were detected. For a new package this is a transparency and maintenance gap, though it is not evidence of unsafe behavior by itself.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear. This is a modest transparency gap rather than a reason to reject the release alone.
v0.1.1 is not a stable major release, so its API and behavior may still change. It is not marked as a prerelease, providing a small amount of compensating evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.