The workflows use four unpinned references, including a high-confidence unpinned container image, and the repository has no security scanning. A license, tests in the repository, documentation, and a stable release offset those hygiene concerns.
42%
Total Score
25
72
This is the package's only release, published over five years ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, with the repository last pushed in February 2021. This is strong evidence that maintenance has stopped.
The repository is owned by an individual account, not an organization, so the single registry maintainer is not explained by organizational backing. This leaves a thin apparent ownership base alongside the inactivity evidence.
The repository has zero stars and forks and one watcher. Low popularity is supporting evidence rather than a verdict, but it provides little external evidence of maturity or adoption.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest repository-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^8.0 | — | — |
illuminate/support Version ^8.0 | — | — |
illuminate/contracts Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.