The package includes tests, a clear README, and an MIT license. Its three releases arrived within about 1 hour 17 minutes, followed by no commits in the last 3 months and no visible security policy or scanning.
65%
Total Score
50
88
83
The repository and registry are owned by the same individual account. This is consistent ownership, but it does not provide organizational backing to offset the limited observed activity.
All three releases were published on the same day, with a median interval of about 1 hour 17 minutes, and the package is now about 174 days old. This looks like an initial release burst rather than sustained release activity.
The repository has had zero commits and zero active maintainers in the last 3 months. Combined with the short initial release burst, this raises the risk that maintenance has stalled.
Composer build tooling is present, but no security scanning tools were detected. For a package that handles token and proxy flows, this is a meaningful but not severe transparency gap.
No security policy was found, leaving contributors and users without a documented vulnerability-reporting path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.