Clear documentation, tests, and licensing make integration easier. Maintenance evidence is limited by no commits in three months, only two releases on one day, and a single registry maintainer. The repository also lacks a security policy and automated security scanning.
62%
Total Score
50
88
83
One registry maintainer is a thin publishing base. The linked repository is user-owned rather than organization-owned, so there is no provided backing signal to offset that limitation.
There are only 2 releases, both published on the same day, so the package has too little release history to demonstrate sustained maintenance.
The repository recorded 0 commits and 0 active maintainers in the last three months, despite the package being about 125 days old. That leaves maintenance and abandonment risk materially uncertain.
Composer build tooling is present, but no security-scanning tool was detected. That leaves a modest gap in the project's maintenance and transparency practices.
The linked repository has no security policy, reducing transparency for reporting and handling security issues. This is a hygiene and maintenance concern, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/queue Version ^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.