Usable with caveats: the package is transparently structured, licensed, tested, and actively released, but it is brand new with only two releases and no established commit history. Its single-person backing and lack of security tooling add maintenance risk.
62%
Total Score
63
100
75
88
Only one registry account has publishing access. This is a limited operational base, though the repository is explicitly owned by the same individual rather than an organization.
The registry namespace and repository are tied to the same individual user account, with no organization backing. This is consistent ownership but leaves a narrow support base.
The package is newly published, with two releases on the same day and no longer-term release history. This provides too little evidence of sustained maintenance or stability.
There were no commits and no active maintainers in the three-month activity window. Because the package is only hours old, this mostly reflects insufficient history rather than demonstrated abandonment.
The repository has zero stars, forks, and watchers. This is not disqualifying for a new package, but it provides no external evidence of adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/cache Version ^11.0|^12.0|^13.0 | — | — |
illuminate/config Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.