Usable with caveats: it has a clear README, tests, a matching source repository, stable releases, and no deprecation or install scripts. However, this young package has had no release or repository push for about 3.5 months after five releases in its first four days, and its repository lacks a security policy and explicit workflow token permissions.
62%
Total Score
50
100
78
80
The package and repository are owned by the same individual account rather than an organization, so the project appears to rely on a single personal owner and has limited visible institutional backing.
The package is only 114 days old and all five releases occurred within its first few days; there has been no new release for about 3.5 months, which raises a maintenance concern for a new integration package.
The repository has zero stars, forks, and watchers. This provides no external adoption evidence, though popularity is supporting evidence rather than a health verdict by itself.
Composer build tooling is present, but no security scanning tools are configured. The build setup is appropriate, while the missing security automation is a modest transparency and maintenance gap.
The linked repository is not archived, but its last push was about 3.5 months ago, consistent with the release-history concern about limited recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.