The package has a useful README, tests, release notes, and a clear MIT license. It has no security policy or scanning, while the absence of recent project activity leaves maintenance uncertain.
42%
Total Score
0
79
75
The package has five releases, but none in the last 12 months and its latest release was about five years ago. This indicates a substantial abandonment risk despite its established age.
The repository had zero commits and zero active maintainers in the last three months, consistent with no meaningful activity since May 2021. The non-archived status does not compensate for this prolonged inactivity.
Composer build tooling is present, which supports reproducible project setup, but no security scanning tools are configured. That weakens ongoing transparency and review for a package that can run as a server component.
The repository has no security policy. This is a transparency gap for a server-oriented package, although it is less severe than evidence of an active vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
inhere/console Version ^3.0 | — | — |
illuminate/http Version ~5.1 | — | — |
illuminate/console Version ~5.1 | — | — |
illuminate/support Version ~5.1 | — | — |
illuminate/contracts Version ~5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.