Its declared GPL-3.0 conflicts with the detected Apache-2.0 license, and the repository has no security policy. A README and tests provide some context, but do not offset the replacement recommendation.
18%
Total Score
0
50
75
Packagist marks the entire package as abandoned and names leskhq/lesk-modules as its replacement. This is a severe adoption risk because the assessed package is no longer the maintained distribution.
The latest release was published in July 2017, with no releases in the last 12 months. This indicates prolonged release abandonment for a framework integration package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. There is no recent development evidence to compensate for the age of this release.
The manifest declares GPL-3.0, while the artifact license file was detected as Apache-2.0. The package is licensed, but the mismatch creates legal ambiguity for adopters.
The linked repository name does not match the package name and its README does not mention this package. That weakens provenance confidence, even though the repository is organization-owned and may represent a renamed or replacement project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/config Version 5.1.*|5.2.* | — | — |
illuminate/routing Version 5.1.*|5.2.* | — | — |
illuminate/support Version 5.1.*|5.2.* | — | — |
illuminate/database Version 5.1.*|5.2.* | — | — |
illuminate/filesystem Version 5.1.*|5.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.