Install-time scripts and the absence of security tooling or a security policy add avoidable operational risk. The MIT license, stable release status, and matching repository are positive, but pinning this version is prudent.
44%
Total Score
50
81
50
The package runs post-install and post-update commands, increasing installation complexity and the amount of package code executed automatically.
One registry maintainer provides little publishing redundancy, although the linked repository is identified with the same project and owner context.
The package has had no release in nearly two years, and all nine releases arrived within a very short period; this suggests limited ongoing maintenance capacity.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release hiatus and raising abandonment risk.
The repository has zero stars and forks and only one watcher, providing little community evidence to offset the lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0 || ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.