Usable with caveats: the package is actively publishing, licensed, backed by an organization, and has repository tests, but it is only 87 days old and all recent commits come from one contributor. The repository also lacks a security policy, so adoption deserves routine review.
72%
Total Score
63
100
94
88
Only one registry account has publish access, which limits publishing redundancy, although the repository is owned by an organization that can provide broader project backing.
The package is young at 87 days and has four releases, with releases clustered closely together; this shows active initial development but limited evidence of long-term maturity.
One contributor made all three commits in the last three months, creating a concentrated maintenance dependency; organization ownership partially offsets the risk but does not remove it.
The repository recorded three commits in the last three months, showing some activity, but only one active maintainer provides limited evidence of sustained maintenance capacity.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a package handling privacy-related workflows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/queue Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.