Usable with caveats: the package is licensed, transparently sourced, tested in the repository, and not deprecated, but it has had only one registry release with no commits in the last three months. A single maintainer and permissive GitHub workflow settings add maintenance and operational risk.
61%
Total Score
50
100
89
60
One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script-injection pattern was detected, so this is a workflow caution rather than a severe health risk.
The package runs a post-autoload-dump install-time script, which adds some installation complexity and trust exposure, though this alone is not evidence that the package is unsafe to depend on.
Only one registry publishing account is listed, creating a narrow operational base if that maintainer becomes unavailable. The linked repository is user-owned rather than organization-owned, so there is no organization backing shown to offset this concern.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization, so the evidence shows direct ownership without broader institutional backing.
Only one release has been published, and it was approximately 17 months before collection, leaving little evidence of sustained release maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.