Documentation, licensing, tests, and release notes are in place, with a focused dependency set and matching source repository. The project is brand new, and all six workflow actions are unpinned, so maintenance history and build reproducibility remain limited.
72%
Total Score
75
100
88
67
The package is only 0 days old with three releases published within the same day, so there is not yet enough history to demonstrate sustained maintenance.
No commits or active maintainers were recorded over the last three months, but the repository is newly published, making this an insufficient maintenance-history concern rather than evidence of collapse.
Composer and Make tooling are present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, which weakens disclosure guidance for consumers, though this is a hygiene gap rather than a direct dependency risk.
Both workflows use read-only permissions and the audit found no injection or other findings, but all six action references are unpinned, reducing build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
illuminate/validation Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.