The package includes tests, a clear README, stable versioning, and a matching source repository. Unpinned workflow actions and absent security tooling add smaller maintenance concerns.
61%
Total Score
50
100
83
67
The repository is owned by a user account rather than an organization, so there is no demonstrated organizational backing to compensate for the thin maintenance record.
The package has only four releases across about seven months, with the latest release about six months ago and releases arriving in a short burst. That limited and inactive history raises maintenance risk.
There were no commits and no active maintainers in the last three months, while the latest push aligns with the release about six months ago. This is the strongest evidence of currently limited maintenance.
The repository has no stars, forks, or watchers. Popularity is only supporting evidence, but this provides no community signal to offset the inactive commit history.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a release blocker.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/cache Version ^12.0|^13.0 | — | — |
illuminate/config Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.