It has tests, documentation, an MIT license, and a repository that matches the package. However, development and releases stopped in August 2019, and there is no security policy; the install-time script also adds maintenance and review risk.
55%
Total Score
50
92
67
The package defines a post-install-cmd script, which introduces execution during installation and deserves review. No other provided signal shows that this script is unsafe, so the effect is limited to caution.
The package has 9 releases since December 2017, but none in the last 12 months and its latest release was in August 2019. This long period without releases is a substantial abandonment concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no activity since August 2019. This materially lowers confidence in ongoing maintenance.
The repository has no security policy. For a validation library this is a transparency gap, although the package does include tests and a documented consumer-facing README.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.3 | — | — |
illuminate/validation Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.