Documentation and testing are strong, and releases remain active. A single maintainer, no security policy, and four unpinned workflow actions leave modest maintenance and build-integrity concerns.
76%
Total Score
63
100
94
75
Only one registry maintainer is listed. That is workable for a small package but leaves publishing continuity dependent on one person.
The repository is owned by an individual rather than an organization, so the single-maintainer and concentrated-contributor concerns are not offset by visible organizational backing.
All three recent commits came from one contributor, so maintenance knowledge and release capacity are concentrated in a single person.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version >=8.0 <14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.