Usable with caveats: the package is licensed, documented, not deprecated or archived, and its repository matches the package. Maintenance is thin, with one release in the last year and all recent commits from one contributor, while the repository lacks a security policy.
68%
Total Score
50
100
88
75
The registry namespace and repository are owned by the same individual account, confirming direct ownership but providing no organizational maintenance backing.
The package is established enough to have seven releases over 489 days, but only one release occurred in the last 12 months, indicating limited recent release activity.
All recent commits came from a single contributor, leaving maintenance dependent on one person; the repository is user-owned, so there is no organization backing to offset that concentration.
There was one commit in the last three months from one active maintainer; this shows some activity but provides limited evidence of sustained maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~9.0 || ~10.0 || ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/notifications Version ~9.0 || ~10.0 || ~11.0 || ~12.0 || ~13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.