Healthy and reasonable to use, with the usual early-project caveat. It has one recent release, active repository work, tests, documentation, security tooling, and a clear license, but all 17 recent commits came from one contributor and the project has little adoption history.
78%
Total Score
75
100
94
90
The package and repository are owned by the same individual account rather than an organization, so there is no visible organizational maintenance buffer. Recent commits and the complete project structure provide partial practical support.
This is a young package, first released 39 days ago, with only one release and no established release cadence. The repository's recent commit activity partly offsets the limited release history, but long-term stability remains unproven.
All 17 recent commits came from one contributor, giving the project a single point of failure if that person stops maintaining it. This is the main ongoing maintenance risk for an individual-owned project.
All three workflows lack top-level permissions declarations. Although none requests top-level write access, explicitly restricting workflow tokens would improve CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^8.83 || ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
illuminate/support Version ^8.83 || ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
illuminate/database Version ^8.83 || ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
illuminate/pipeline Version ^8.83 || ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
illuminate/contracts Version ^8.83 || ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.