It includes a readable guide, tests, a matching MIT license, and a repository that clearly belongs to it. The evidence is too recent to establish a maintenance track record, and both workflow actions are unpinned.
68%
Total Score
75
88
50
Five releases arrived within a few hours and the package is only hours old, showing active initial publishing but no meaningful long-term release history yet.
There are no commits or active maintainers recorded in the last three months. Because the repository is only hours old, this is weak evidence rather than proof of abandonment, but it leaves maintenance unestablished.
Composer build tooling is present, but no security-scanning tool is configured. That is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy, leaving vulnerability reporting expectations undocumented for a package that monitors applications and servers.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
illuminate/process Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.