The package is very new, so its long-term maintenance record is still unproven. It has release notes, a matching repository, and no install-time scripts; proprietary licensing and missing security tooling warrant extra review.
62%
Total Score
50
100
81
83
The manifest declares a proprietary license, so the release is licensed, but no license file was detected in the package or repository. This limits transparency and may impose usage restrictions that developers should verify.
The package and repository are owned by the same individual account. That is consistent ownership, but it provides less organizational redundancy than an organization-backed project.
The package is 0 days old with only 2 releases, so there is not yet enough history to demonstrate sustained maintenance. The rapid v1.0.0-to-v1.0.1 release sequence is a small positive but does not offset the lack of longevity.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package itself is newly published, this is partly explained by its age, but it leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tools were detected. For a package handling installation and license validation, the missing security tooling is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/view Version ^12.0 || ^13.0 | — | — |
illuminate/cache Version ^12.0 || ^13.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
illuminate/routing Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.