A clear README, release notes, and matching repository make integration easier. The single-maintainer project has no commits in about three months and no security policy or scanning, so ongoing support is uncertain.
62%
Total Score
50
100
88
75
Only one account has registry publish access. Because the repository is user-owned rather than organization-backed, this indicates a thin publishing and support base.
The repository is owned by an individual account, not an organization. That is consistent with the single maintainer and provides limited evidence of institutional continuity.
The package published five releases within about one day, then had no newer release for roughly five months. This shows initial activity but leaves its ongoing maintenance cadence unproven.
The repository recorded zero commits and zero active maintainers in the last three months. For a package only about five months past its initial release, this is a meaningful maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. That weakens ongoing security oversight, although it is not evidence of malicious behavior by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.