The project released this version recently and has an organization behind it, but recent work comes from one contributor. Workflow references are all unpinned, and the audit found a low-confidence cache risk; no security policy is published.
68%
Total Score
83
100
94
50
All three recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some ability to hand maintenance off, so this is a caution rather than a severe abandonment signal.
The project uses Composer and Make, but no security-scanning tools were detected. This is a transparency and hygiene gap, not evidence that the release is unsafe.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a network-facing RPC integration.
The single workflow was fully analyzed and has no untrusted checkout or script-injection path, but all five action references are unpinned. The auditor also reported a high-severity cache-poisoning pattern with low confidence, which warrants hygiene caution rather than a severe conclusion.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/routing Version ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/support Version ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/contracts Version ~11.0 || ~12.0 || ~13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.