The repository is small, clearly tied to the package, and has a useful README. The declared MPL-2.0 conflicts with the MIT license found in the artifact, while the project has no tests, security policy, or security scanning.
55%
Total Score
50
71
75
A license file is present, but the manifest declares MPL-2.0 while the artifact license file is detected as MIT. This inconsistency makes the release's licensing terms less transparent.
Only one registry maintainer is listed. The linked repository is user-owned rather than organization-backed, so there is limited visible succession capacity if the maintainer stops work.
The package has 14 releases, but none in the last 12 months; its latest release was on October 30, 2024. This indicates a meaningful maintenance slowdown for a Laravel library.
The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with the package's stale release history. The repository is not archived, but there is no recent development evidence.
The repository has 3 stars, 0 forks, and 1 watcher. Low adoption is supporting evidence of limited maturity, though it is not by itself a reason to reject a small, maintained package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^v11.27.2 | — | — |
intervention/image Version ^3.8.0 | — | — |
illuminate/database Version ^v11.27.2 | — | — |
illuminate/pipeline Version ^v11.27.2 | — | — |
illuminate/contracts Version ^v11.27.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.