The package has thorough documentation, tests, changelog coverage, and recent release notes. Its pre-1.0 status and reliance on one main contributor warrant pinning the version and watching future changes.
78%
Total Score
70
100
89
83
Only one registry account has publish access. That is a modest publishing bus factor, although repository activity shows a second active contributor and the linked source is directly maintained by the same owner.
The repository is owned by an individual account, not an organization, so the highly concentrated commit activity is not offset by clear organizational handoff capacity.
One contributor made 29 of 30 commits in the last three months, so maintenance is highly concentrated. A second contributor is active, but the 97% concentration still creates continuity risk for an individual-owned project.
Composer build tooling is present, but no security-scanning tool was detected. This is a moderate transparency and hygiene gap rather than evidence of unsafe code.
The repository has no security policy. For a workflow engine that handles credentials and application integrations, this weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/mail Version ^12.0|^13.0 | — | — |
illuminate/queue Version ^12.0|^13.0 | — | — |
illuminate/events Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.