The package has a small dependency surface, repository tests, and matching project ownership. Its workflow references are unpinned and the repository has no security policy, so pinning this version warrants extra care.
58%
Total Score
75
100
71
50
The latest release was in December 2022, nearly four years before collection, and there were no releases in the last 12 months. Eight releases show some history, but the current cadence indicates meaningful maintenance risk.
There were no commits and no active maintainers in the three months before collection. The later repository push date is compensating context, but recent activity remains weak.
Composer is used for the build, but no security scanning tools are present. The build setup is appropriate, while the missing scanning is a modest hygiene gap.
The repository has no security policy. This limits disclosure transparency, though it is a hygiene concern rather than evidence that the package is unsafe.
v0.3.0 is not a prerelease, but it remains below the 1.0 major line and half of recent versions were prereleases. This lowers maturity confidence without making the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0 | — | — |
illuminate/contracts Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.