The Apache-2.0 license, matching repository, and organization backing provide useful transparency. It is a brand-new package with no maintenance track record, and the repository has no security policy or scanning tooling yet.
72%
Total Score
75
100
83
88
This is the first release, published today, so there is no release cadence or history to demonstrate sustained maintenance. Its age makes the absence of history understandable rather than evidence of abandonment.
There were no commits or active maintainers in the past three months, but the repository was created or pushed today. This leaves maintenance capacity unproven rather than showing a collapsed established project.
The repository has zero stars, forks, and watchers. For a package published today this is mainly a lack of adoption evidence, not a strong negative maintenance signal.
Composer is used as the build tool, fitting the package ecosystem, but no security scanning tool was detected. That is a modest transparency and hygiene gap.
The repository has no security policy. This matters for reporting and response expectations, though the package is a small type-definition metapackage with no demonstrated security process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/illuminate-mail-impl Version ~13.32.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.