The repository has tests, a changelog, release notes, a security policy, and a matching package reference. Its dependency set is small and the release is licensed, but the project is still too new for a strong long-term maintenance record.
65%
Total Score
50
100
88
75
A post-autoload-dump install-time script is present. This is a modest supply-chain surface increase, but the signal gives no evidence that the script is unsafe.
The repository owner is an individual rather than an organization, so the single-contributor maintenance concentration is not visibly offset by organizational backing.
The package is only 56 days old with two releases and a median interval of about 7 days, so its release pattern is promising but its maintenance history is still short.
One contributor made all four recent commits, leaving maintenance highly concentrated and increasing continuity risk for this young project.
There were four commits in the last three months, showing recent activity, although the limited volume provides only modest evidence of sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^12.0 | — | — |
illuminate/support Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.