This release appears suitable for dependency use: it is a stable, MIT-licensed package with substantial documentation, tests, a changelog, a coherent source repository, and strong recent maintenance activity. The package has had 50 releases over 312 days, including 50 in the last 12 months, and the repository recorded 143 commits from three active contributors in the last three months. The main reservations are concentrated ownership, with one contributor responsible for about 79% of recent commits, and limited security-process transparency because no security policy or security scanning tooling was found. These concerns warrant normal release review and monitoring but do not indicate abandonment or an otherwise unfit dependency.
82%
Total Score
70
100
94
90
Only one registry account has publish access. This is a caution for release continuity, though it is partly offset by three active repository contributors and should not be treated as a maintenance verdict by itself.
The source repository is owned by a personal user account rather than an organization, so the concentrated contributor activity and single registry maintainer are not offset by visible organizational backing.
Recent activity is concentrated: the top contributor made about 79% of commits. Two additional contributors remain active, which provides some resilience but leaves a meaningful single-maintainer dependency.
Composer build tooling is present, but no security scanning tools were found. The missing security automation is a transparency gap, although it is not evidence of unsafe code by itself.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.11 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/queue Version ^12.0|^13.0 | — | — |
illuminate/events Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.