The package is clearly licensed, documented, and tied to a matching source repository. Its small maintainer base, missing security policy, and install-time scripts add modest adoption and maintenance concerns.
52%
Total Score
38
100
81
67
There were zero commits and zero active maintainers in the last three months, a significant warning that maintenance may have stopped after the initial release burst.
post-install-cmd and post-update-cmd scripts run during dependency installation or updates, adding supply-chain and installation-behavior exposure that should be understood before adoption.
Only one registry account has publish access. That is a thin publishing base for a component library, although repository activity is the stronger evidence of maintenance capacity.
The source repository is owned by an individual account rather than an organization, so there is no visible organizational backing to offset the thin maintainer base.
Five releases were published over about one day, but the latest release is about six months before collection; this suggests an initially active project with no demonstrated ongoing release cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^10.0|^11.0|^12.0 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/filesystem Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.