The package is clearly documented, MIT-licensed, and backed by repository tests, a changelog, and a security policy. Its CI has a high-confidence unpinned container image, adding a smaller supply-chain hygiene concern.
38%
Total Score
0
63
50
Only two releases were published, both within about five days in June 2021, with no releases in the last 12 months. This strongly suggests the package is no longer maintained.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing no activity since June 2021. This is a substantial abandonment risk.
The repository is not marked archived, which preserves a possibility of future maintenance, but its last push was in June 2021 and does not offset the prolonged inactivity.
All eight analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in the PHP CS Fixer workflow. There are no untrusted checkouts or script injections, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^7.0|^8.0 | — | — |
illuminate/queue Version ^7.0|^8.0 | — | — |
illuminate/support Version ^7.0|^8.0 | — | — |
illuminate/database Version ^7.0|^8.0 | — | — |
illuminate/validation Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.