The package includes tests, a README, MIT licensing, and repository security scanning. Its small runtime dependency set and matching source repository help, but the young project shows little evidence of sustained maintenance after its initial release burst.
56%
Total Score
33
100
94
83
The repository recorded zero commits and zero active maintainers during the last three months. For a package only 175 days old, this is meaningful evidence that maintenance may have stopped.
Only one registry account has publish access. Because the repository is user-owned rather than organization-backed, this leaves a thin publishing and continuity base.
The registry namespace and repository owner are the same individual account. This confirms ownership alignment but provides no organizational backing to offset the single-maintainer risk.
The package is young at 175 days and published 10 releases, all within roughly 26 minutes of one another, with no later releases observed. That initial burst does not demonstrate sustained maintenance.
No security policy is present in the repository. This weakens the documented process for reporting vulnerabilities, though it is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.