Its MIT license, tests, release notes, and matching repository improve transparency. A single maintainer and no repository security policy leave limited resilience if maintenance stops.
60%
Total Score
50
100
78
75
Only one registry maintainer is listed. That is consistent with a personal project but leaves little visible publishing redundancy if the maintainer becomes unavailable.
The package is about 8 months old but has only one release, with no follow-up version after the initial v0.1.0. That is meaningful evidence of limited maturity for a dependency.
There were zero commits and zero active maintainers in the last 3 months. For a young package, that weakens evidence of ongoing maintenance, although it does not by itself prove abandonment.
The repository has 2 stars, no forks, and no watchers. This is weak supporting evidence of adoption, but popularity alone does not determine whether a small package is healthy.
Composer build tooling is present, but no security scanning tools are reported. That is a hygiene gap rather than a direct dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^8.0|^9.0|^10.0|^11.0 | — | — |
illuminate/http Version ^8.0|^9.0|^10.0|^11.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.