The package has clear documentation, tests in the repository, a license, and no install-time scripts. Its main limitations are that it is newly published, has one active contributor, lacks a security policy, and uses six unpinned workflow actions.
68%
Total Score
50
100
83
75
Only one account has registry publish access. This is a limited publishing base, though registry access alone does not establish the project's actual maintenance capacity.
The repository is owned by an individual user, not an organization. Combined with the single-contributor activity, this provides limited evidence of maintenance handoff capacity.
This is the first release and the package is 0 days old, so there is no meaningful release track record or evidence of sustained maintenance yet.
One contributor made all three commits in the measured period, leaving maintenance fully concentrated in a single person. The repository is user-owned rather than organization-owned, so there is no provided backing signal to offset that concentration.
There were three commits in the last three months, all around the initial release, with one active maintainer. This shows current activity but not sustained maintenance over time.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.