The package is newly published with no release track record, tests, or repository security policy. It does include a README, uses a declared MIT license, has a matching repository mention, and has no install-time scripts or workflow audit findings.
68%
Total Score
50
100
81
83
One registry publishing account is listed. This is limited publishing redundancy, but the linked repository is owned by an individual, so it provides only modest evidence of maintenance capacity.
The repository is owned by an individual account rather than an organization, and the registry namespace does not establish organizational backing. This leaves limited visible backing for a brand-new package.
This is the first release, published 0 days ago, so there is no track record yet for maintenance or release stability. Its age limits the evidence but does not by itself show abandonment.
The repository has zero stars, forks, and watchers. Because the package is 0 days old, this mainly reflects its newness rather than established abandonment.
The repository uses Composer, but no security-scanning tools were detected. That is a transparency and hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.8|^8.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.