It includes tests, a usable README, and a small dependency set, while the repository is not archived. The missing license and absent security practices leave important transparency and maintenance gaps.
55%
Total Score
50
81
75
No license is declared, no license file is present in the package, and no repository license file was found. This creates a concrete adoption and transparency problem for an open-source dependency.
The package has seven releases over about seven years, but none in the last 12 months; its latest release was about 17 months ago. This indicates a meaningful slowdown, despite a previously established release history.
The repository recorded zero commits and zero active maintainers in the last three months. The repository was pushed around the latest release, but current development activity is absent.
Composer build tooling is present, but no security-scanning tool was detected. The build setup is a positive, while the missing security automation modestly weakens maintenance hygiene.
The repository has no security policy. For a small package this is a hygiene gap rather than evidence of unsafe code, but it reduces transparency about vulnerability reporting and maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^v10.48.28 | — | — |
illuminate/database Version ^v10.48.28 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.