Clear documentation, tests, and licensing make integration easier. Composer dependencies are moderate and installation runs no lifecycle scripts. Operational security practices are limited, so future maintenance deserves attention.
68%
Total Score
50
100
86
75
The package is only 90 days old, but it has already published 7 releases, including 7 in the last 12 months and a median interval of about 1 day. This shows active early development, though long-term maintenance is not yet demonstrated.
One contributor made 100% of the 12 commits in the last 3 months. Because the repository is user-owned rather than organization-owned, there is no provided backing signal to offset this concentration.
The repository recorded 12 commits in the last 3 months, showing recent activity. However, all activity is concentrated in one active maintainer, which limits evidence of durable maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance concern, not evidence that the release is unsafe.
The repository has no security policy. For a package handling subscription and access-control business logic, this leaves vulnerability-reporting expectations and response procedures unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/events Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.