The repository has had no commits in three months, and only two releases were published in the last year. MIT licensing, a clear README, a matching repository, and organization backing provide useful transparency, but there are no tests or security scanning tools.
64%
Total Score
75
100
83
88
Only one registry account has publish access, which is a limited publishing base. Organization backing partly offsets this concern because the repository is owned by an organization.
The package has 23 releases over roughly two years, but only 2 in the last 12 months; this suggests slower recent maintenance without proving abandonment.
The repository recorded 0 commits and 0 active maintainers in the last three months, a concrete sign that maintenance has slowed recently.
The repository has 0 stars and 0 forks, with 2 watchers. This indicates limited adoption evidence, but popularity is supporting evidence rather than a health verdict.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.