The MIT license, substantial README, tests, changelog, and matching repository provide good transparency. There is no security policy or automated security scanning, so safeguards are still limited.
62%
Total Score
50
81
75
This is the package's first release, published 0 days ago, so there is not enough history to demonstrate sustained maintenance. Its age also means the lack of follow-up releases is not yet evidence of abandonment.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package was published 0 days ago, this primarily shows that ongoing maintenance has not yet been demonstrated rather than proving abandonment.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful security-hygiene gap for a package intended to run inside applications.
The repository has no published security policy. This weakens vulnerability-reporting transparency, although the package's license, tests, and documentation provide other forms of project transparency.
The v0.1.0 version indicates an early-stage project rather than a mature stable release. It is not marked as a prerelease, which provides some compensation but does not establish long-term stability.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/queue Version ^11.0|^12.0|^13.0 | — | — |
illuminate/events Version ^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.