The package has a long release history, a current stable release, tests in its repository, and an identifiable organization owner. Recent commit activity is absent, workflow actions are entirely unpinned, and no security policy is published.
45%
Total Score
75
83
50
The package is reported as borrowing laravel/tinker's identity, even though artifact overlap is 0.0 and the README does not identify it as a lookalike. Under the supplied identity signal, this is a severe adoption risk because consumers may have intended the established package.
The package uses a post-autoload-dump install-time script. This is common Composer integration behavior, but it adds execution during installation and merits normal dependency review.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The recent release history and non-archived state partly compensate, but the current maintenance pause remains a concern.
Composer build tooling is present, but no security-scanning tools were detected. Build structure is clear, while automated security coverage is limited.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is not evidence that the package is abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/http Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/config Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.