The package is clearly documented and includes a license, changelog, and substantial source tree. Its single-person ownership, absent security scanning and policy, and zero commits in the last three months leave maintenance and response capacity uncertain.
62%
Total Score
50
100
83
75
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is limited visible publishing continuity if that maintainer becomes unavailable.
The repository owner is an individual user rather than an organization, which provides less visible institutional backing for a security-sensitive dependency.
There have been 13 releases in about seven months, but the median interval is about 3 hours 46 minutes, suggesting a concentrated burst rather than established long-term cadence.
The repository has zero commits and zero active maintainers in the last three months. For a package with a recent release, this is a meaningful warning about ongoing maintenance capacity.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for community review, but the package is still relatively young, so it is not decisive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.