A single registry maintainer and no commits in the last three months reduce resilience if maintenance stops. The release remains documented, tested, licensed, and linked to an active, non-archived project.
64%
Total Score
50
100
83
63
The package runs a post-autoload-dump install-time script. Its behavior is not shown here, so this adds a small supply-chain review concern without proving harmful activity.
Only one account has registry publish access. The linked project is user-owned rather than organization-backed, so there is little visible publishing redundancy.
The registry namespace and repository owner match, but the owner is an individual account, so the project has limited visible organizational backing.
The package has existed for about 7 years and has 13 releases, but only one release in the last 12 months and a median interval of about 170 days indicate slow maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of recently stalled development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0 | — | — |
illuminate/database Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.