The package includes a substantial README, tests, changelog, and a matching repository, which support practical adoption. Composer install hooks, no security policy, and the artifact's oversized dependency tree leave modest review and maintenance gaps.
58%
Total Score
71
50
The artifact contains a license file and declares MIT, which is positive; however, detected MIT and ISC text does not exactly match the declared license and warrants a small transparency check.
The package defines post-install and post-update Composer scripts. These may be legitimate, but they add install-time behavior that consumers should understand before adoption.
The package includes more than 17,000 files, including node_modules and system/cache artifacts such as .DS_Store and PHPUnit cache files. This is poor release hygiene and increases artifact size and review burden.
Only one release exists, published about 13 months ago, with no releases in the last 12 months. That leaves maintenance continuity unproven for a package intended as a Laravel integration.
Composer is used as the build tool, but no security-scanning tooling is present. That is a modest project-hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/filesystem Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.