Documentation, licensing, tests, and a clear package layout support adoption. The missing security policy and concentrated contribution pattern leave more continuity risk than a mature project would normally carry.
78%
Total Score
67
100
94
88
The registry namespace and repository owner match, but both belong to a user account rather than an organization. This supports ownership consistency but provides limited evidence of institutional maintenance capacity.
One contributor made 23 of 24 recent commits, or about 96%, while the second made one. The active second contributor partly offsets the concentration, but continuity still depends heavily on one person.
Composer build tooling is present, but no security scanning tools were detected. The missing automated security checks are a transparency and maintenance weakness, not a severe risk by themselves.
The repository has no security policy. For a package handling cloud API credentials, this leaves vulnerability-reporting expectations less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ubxty/core-ai Version ^2.2 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/cache Version ^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.