Usable with caveats: the release is licensed, documented, tested, and not deprecated or archived, but it has only two releases in nearly a year and no commits or active maintainers in the last three months. The absence of security scanning and a security policy adds a smaller transparency concern.
62%
Total Score
50
88
83
The package and repository are owned by the same individual account, providing direct ownership alignment, but there is no organization backing to broaden maintenance capacity.
Only two releases have been published across 327 days, with a median interval of about 328 days. That sparse release history limits evidence of sustained maintenance and timely fixes.
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance concern, although the recent repository push and one merged pull request provide limited compensating evidence.
Composer build tooling is present, but no security scanning tools were detected. For a package that sends messages and handles provider integrations, this is a modest transparency and maintenance gap.
The repository has no security policy. This makes vulnerability-reporting expectations less clear, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^12.0 | — | — |
illuminate/http Version ^12.0 | — | — |
illuminate/queue Version ^12.0 | — | — |
illuminate/support Version ^12.0 | — | — |
illuminate/contracts Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.