The package includes substantial documentation, repository tests, release notes, and security tooling. Its license files and Composer install hook deserve a closer look before adoption.
68%
Total Score
67
79
75
The package declares MIT and includes license files, but the artifact also identifies Apache-2.0, leaving a license coverage mismatch that should be clarified.
The package runs a post-autoload-dump install-time script. The signal provides no script details, so this is a limited supply-chain hygiene concern rather than evidence of harmful behavior.
The package is only 60 days old but has four releases, including recent activity, which shows an active launch phase without yet demonstrating long-term maintenance.
One contributor holds all six recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown, so the concentration remains a maintenance risk.
Six commits in the last three months show recent work, but all activity comes from one active maintainer, limiting evidence of durable maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.