Tests, documentation, release notes, and a matching repository provide a solid starting point. The project is brand new with no three-month commit history, and all 10 workflow actions are unpinned; the missing security policy is a smaller transparency gap.
68%
Total Score
88
100
83
75
This is the first release, published on September 28, 2026, so there is no release track record yet. That limits confidence in long-term maintenance, although the package has a matching repository and release notes.
There were no commits and no active maintainers during the last three months, but the repository and release are both brand new. This weakens the maintenance record without proving abandonment.
The repository has zero stars, forks, and watchers. For a package released on the assessment date, that is limited supporting evidence rather than a decisive health problem.
Composer build tooling is present, while no security scanning tools were detected. The build setup is appropriate, but the absence of automated security scanning leaves a modest process gap.
No repository security policy was found. That reduces vulnerability-reporting transparency, though the package's tests, documentation, and license provide compensating project structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.