The package includes a clear README, no install-time scripts, and an organization-backed repository. Its proprietary license and zero commits in the last three months create meaningful adoption and maintenance concerns.
52%
Total Score
75
100
81
83
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. That limits transparency and may restrict dependable reuse despite the package being published through an open-source ecosystem.
The package is young at 153 days old but has 12 releases in the last 12 months, showing active publishing. The very short median release interval of about 1 hour 21 minutes suggests rapid release churn rather than a mature cadence.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was recently pushed and released, the absence of recent commit activity weakens evidence of ongoing maintenance.
The repository uses Composer, appropriate for a Packagist package, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
No security policy was found in the repository. This reduces disclosure transparency, but it is a secondary concern alongside the licensing and maintenance evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^13.0 | — | — |
illuminate/database Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
spatie/laravel-permission Version ^6.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.