Install-time scripts increase update exposure, while the MIT declaration and active repository are positives. No security policy or security scanning leaves limited assurance.
0%
Total Score
50
75
67
post-install-cmd and post-update-cmd scripts run during dependency changes, increasing the package's operational and update exposure.
This release is only 48 days old and the package has just one release, so there is little evidence of sustained maintenance or release discipline.
All 7 commits in the last 3 months came from one contributor, leaving maintenance dependent on a single person.
The repository name does not match the package name and its README does not mention the package, so the repository's ownership of this package is not clearly established.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version >=10.0 | — | — |
illuminate/console Version >=10.0 | — | — |
illuminate/support Version >=10.0 | — | — |
illuminate/filesystem Version >=10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.