The package is clearly documented, tested, licensed, and backed by an organization, with no deprecation or install-time scripts. Its young project history and absent security safeguards leave maintenance and transparency less proven.
68%
Total Score
75
81
75
This is a young package with one release over its 100-day history, so there is not yet enough release evidence to establish a dependable maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months. For a package only about 100 days old, this is a meaningful sign that ongoing maintenance is unproven.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy, leaving the process for reporting and handling vulnerabilities undocumented.
The assessed version is v0.2.0 rather than a stable major release, which indicates an API that may still change even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^10.0 || ^11.0 || ^12.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 | — | — |
serpcheap/serpcheap Version ^0.2 | — | — |
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.