Healthy and reasonable to depend on. It has a current stable release, a matching organization-backed repository with recent commits, tests, release notes, and a clear license; the main caveats are modest release frequency and limited security-policy and workflow-permission hardening.
82%
Total Score
100
86
50
The repository has only 1 star and 7 forks, indicating limited adoption evidence. Popularity is supporting evidence rather than a decisive health measure, and the recent release and project practices compensate for the small audience.
The project uses Make and Composer, but no security-scanning tools were detected. This is a transparency and hardening gap, though it is not severe given the other repository evidence.
No repository security policy was found, leaving vulnerability-reporting guidance unclear. This lowers transparency but does not by itself indicate that the package is unsafe to depend on.
The single workflow has no top-level GitHub Actions token permissions declaration. No write permissions or dangerous workflow patterns were detected, but explicitly restricting permissions would provide stronger build-security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.2 | — | — |
guzzlehttp/guzzle Version ~7.5 | — | — |
illuminate/config Version ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/support Version ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/contracts Version ~11.0 || ~12.0 || ~13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.