The project is young, has one registry maintainer, and its repository has tests and clear usage documentation. Unpinned workflow actions and no security policy add maintenance and build-transparency concerns.
57%
Total Score
67
79
50
The package runs a post-autoload-dump install-time script, which adds execution during installation and warrants attention even though no harmful behavior is shown here.
Only one account has registry publish access, limiting publishing redundancy, though the repository is also owned by that same individual.
The package is about 173 days old with only two releases, although the roughly four-day interval between releases shows an initial burst of activity.
The repository recorded zero commits and zero active maintainers in the last three months, indicating activity has stalled after the initial releases.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.