Documentation and release notes make the upgrade understandable. The project has organization backing, but maintenance is concentrated in one recent contributor and no security policy is published.
72%
Total Score
67
93
50
The package is mature, with 59 releases since 2018 and a release in the last two months, but only 2 releases in the last 12 months indicates a slower cadence.
All recent commits came from one contributor, creating concentration risk; organization ownership provides some handoff capacity but no second recent contributor is shown.
Only 1 commit from 1 active maintainer appeared in the last 3 months, which is sparse for a library and raises maintenance-continuity concerns.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities in a security-sensitive settings package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version >=5.8|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version >=5.8|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/encryption Version >=5.8|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/validation Version >=5.8|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.