The project has clear licensing, tests, a changelog, and a matching organization-owned repository. Its slow release pace, no commits in the last three months, absent security policy, and unpinned workflow actions leave meaningful maintenance and build-hygiene concerns.
65%
Total Score
75
100
83
50
The package has existed for about 7 years but has only 9 releases, with 1 release in the last 12 months and a median interval of about 363 days. That is a slow cadence for a maintained dependency and lowers confidence in timely fixes.
There were 0 commits and 0 active maintainers in the last 3 months. Although a release was published during the broader period, the absence of recent development activity is a maintenance concern.
The repository has 8 stars, 0 forks, and 1 watcher. Low adoption is supporting evidence rather than a defect, but it provides little external signal that the package is actively relied upon.
Composer build tooling is present, but no security scanning tool was detected. This is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/filesystem Version ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminatech/array-factory Version ^1.2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.