Documentation and repository tests are in place, with clear licensing and no install-time scripts. The project is only three days old, and its workflow actions are not pinned, leaving limited evidence of maturity.
68%
Total Score
100
100
88
75
The package is only 3 days old with 5 releases, so it has little demonstrated maintenance history despite a rapid initial release sequence.
Composer build tooling is present. No security scanning tools were detected, which is a modest transparency gap for a new project.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of its 2 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/filesystem Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.