A single publisher and no security policy leave limited maintenance depth. The MIT license, focused README, matching repository, and no install scripts provide useful transparency.
58%
Total Score
50
100
86
83
Only one registry maintainer is listed, and the project is user-owned rather than organization-backed; this leaves limited publishing continuity if that maintainer becomes inactive.
The registry and repository are both tied to the same individual account, confirming ownership alignment but providing no organization-level continuity.
The package is about five months old with four releases, all published within roughly two hours, and no newer release since the initial launch; this suggests limited evidence of sustained maintenance.
The repository recorded no commits and no active maintainers during the past three months, which is meaningful evidence of stalled ongoing development for a recently released package.
There were no issues or pull requests opened or merged in the past month. With no broader activity to compensate, this provides little evidence of an active maintenance community, though the package is small.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.