Tests, release notes, a clear MIT license, and a repository that matches the package provide useful transparency. Maintenance evidence is still thin after a concentrated launch burst, while the workflow leaves two actions unpinned and the repository has no security policy.
68%
Total Score
50
88
75
The package and repository are owned by the same individual account, so the source relationship is clear. Individual ownership provides less demonstrated maintenance capacity than organizational backing, especially alongside limited activity evidence.
There are 24 releases in 88 days, but the median interval is about 7 minutes and the releases are concentrated in the initial launch period. That rapid burst suggests an immature release process rather than established maintenance.
Composer build tooling is present, but no security scanning tools are reported. For a package handling API credentials and application data, the missing scanning coverage is a modest transparency gap.
The repository has no security policy. That does not show a defect, but it leaves vulnerability-reporting and maintenance expectations undocumented for an integration that handles AI credentials and user data.
The only workflow was fully analyzed with no injection or high-severity findings, but both of its two action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own; unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
laravel/sanctum Version ^4.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.