Its workflows use an unpinned container image, and publishing is controlled by one registry maintainer. The MIT license, tests, release notes, security policy, and matching repository provide useful transparency.
61%
Total Score
75
79
75
Only three releases exist, with no release in about three years; that materially increases the risk that this version is aging without maintained updates.
No commits or active maintainers were recorded during the last three months, which weakens the evidence for ongoing maintenance even though the repository is not archived.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
Version 0.3.0 is not a prerelease, but the package remains below a stable 1.0 major version, so compatibility maturity is somewhat limited.
Both workflows were fully audited without untrusted checkouts or script injection, but the PHP-CS-Fixer workflow uses a high-confidence unpinned container image and all four action references are unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/dns Version ^2.0.2 | — | — |
illuminate/support Version ^9.0 || ^10.0 | — | — |
illuminate/container Version ^9.0 || ^10.0 | — | — |
illuminate/contracts Version ^9.0 || ^10.0 | — | — |
illuminate/collections Version ^9.0 || ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.