The package is MIT-licensed and has a matching source repository, but its documentation is only a brief draft and no security policy is provided. Its single-maintainer, low-visibility project offers little evidence of ongoing support.
43%
Total Score
0
60
75
The latest release was published in May 2020, and there have been no releases in the last six years. That long gap materially raises abandonment and compatibility risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release hiatus. There is no provided activity evidence that development has resumed.
A README is present, but it is only 129 characters and says documentation is still in progress. The absence of tests and a changelog is normal for a published artifact and is not treated as a gap here.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of active community use. Popularity is secondary evidence, so this reinforces rather than determines the maintenance concern.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a meaningful transparency gap for a library dependency, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version >=5.5.0 | — | — |
illuminate/support Version >=5.5.0 | — | — |
illuminate/database Version >=5.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.