The repository includes tests and this release has clear notes. Organization backing helps offset the young project’s limited history, but unpinned CI actions and a single active contributor remain concerns.
67%
Total Score
83
100
88
75
The package is only about 12 weeks old with two releases, so its long-term maintenance record is still limited. The latest release was published recently enough to show ongoing activity.
All 20 recent commits came from one contributor, leaving a narrow maintenance base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy, so there is no documented process for reporting vulnerabilities or coordinating fixes. This lowers transparency but is not an immediate dependency blocker.
All three workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all nine action references are unpinned, leaving the CI build exposed to action changes over time.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ^12.0 || ^13.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.