This release is usable but carries meaningful maintenance and governance uncertainty. It has a clear MIT license, a linked non-archived repository, a recent release, repository tests, changelog, and basic Dependabot/build tooling. However, the package has only three releases over roughly 827 days, remains below a stable major version, shows no commits or active maintainers in the last three months, has negligible repository adoption, and is maintained by a single individual. The repository also lacks a security policy and uses broad or undeclared workflow permissions, with one pull_request_target workflow. These concerns do not make the package unfit, but developers should verify ongoing maintenance and pin the dependency rather than treating it as a mature, low-risk foundation.
62%
Total Score
50
100
83
50
Four workflows were analyzed with one pull_request_target workflow, but no untrusted checkouts or script-injection patterns were detected. The special trigger warrants review but is not severe on the available evidence.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so the single-maintainer structure creates a genuine continuity and bus-factor concern.
The package is about 827 days old but has only three releases, with one release in the last 12 months and a median interval of about 414 days. This indicates slow release cadence and limited demonstrated maintenance momentum.
The repository records zero commits and zero active maintainers over the last three months. This is a direct maintenance concern, although the recent package release provides limited compensating evidence.
There are no new or closed issues in the last month and one open pull request, indicating limited visible collaboration or issue-resolution activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.