The package has clear documentation and a license, with a small runtime dependency set. Its very rapid release pace and two-person maintenance base leave less long-term assurance, while workflow hardening is incomplete.
78%
Total Score
75
100
86
50
The package is only 46 days old but has 109 releases, with releases arriving about every 15 minutes. This shows strong activity but an unusually rapid cadence that slightly reduces release-process confidence.
Two contributors are active, but the leading contributor made about 60% of recent commits. This is a modest continuity risk for a user-owned project, though the second contributor provides meaningful backup.
Composer is used as the build tool, but no security-scanning tools were detected. That leaves the project's automated dependency and code-security checks less transparent.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
Both workflows were analyzed without high- or medium-confidence findings, and no untrusted checkout or script injection was detected. However, all seven action references are unpinned and one workflow grants top-level write permissions, creating avoidable maintenance and token-scope risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.