It has a clear README, MIT licensing, repository tests, and no install-time scripts. The release is too new to demonstrate sustained maintenance, and the repository has no security policy or automated security scanning.
68%
Total Score
50
86
75
One registry maintainer is consistent with an individual-owned project, and the project backing signal identifies the repository owner as a user rather than an organization. This leaves a thin maintainer base but is not severe on its own.
This is the first release, published 0 days ago, with only one release recorded. That is expected for a new project but provides no evidence of an established maintenance pattern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Because the package is 0 days old, this is mainly an evidence gap rather than proof of abandonment, but sustained maintenance remains unproven.
Composer build tooling is present, but no security scanning tools were detected. For a package that changes application routing and access control, the missing security automation is a meaningful hygiene gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, especially for a package that handles routes, controllers, and authorization.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/view Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.