The repository includes tests, a README, and release notes, with no install-time scripts or archive status. Its workflow uses three unpinned actions and lacks a security policy, adding hygiene concerns alongside the lack of ongoing activity.
45%
Total Score
0
67
75
This is the only release, published about 3 years and 7 months ago, with no releases in the last 12 months. That strongly suggests abandonment risk for a young package.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and indicating no observed ongoing maintenance.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
No security policy was found in the repository. For a library, this reduces transparency about vulnerability reporting, though it does not by itself show unsafe code.
The release is v0.1.0 and is not marked prerelease, but the low major version and one-release history indicate limited maturity; the release notes provide some documentation but do not offset the lack of subsequent releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^4.0|^5.0|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
illuminate/contracts Version ^5.0|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.