The repository has no security policy, and its workflows use all-unpinned actions with broad write access. The package is well documented, tested, licensed, and not deprecated.
64%
Total Score
50
100
81
75
The package and repository are owned by matching individual accounts. A single-person project can be healthy, but it provides less organizational continuity than a backed team.
The package has only two releases, both published on the same day, despite being about 9 months old. That provides limited evidence of sustained release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. For a package less than a year old, that is a meaningful sign of slowing maintenance.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a modest repository hygiene gap rather than evidence of abandonment.
The repository has no security policy. For a package handling model locking and database migrations, this weakens the project's transparency about reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.0 | — | — |
illuminate/cache Version ^11.0|^12.0 | — | — |
illuminate/support Version ^11.0|^12.0 | — | — |
illuminate/database Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.