The source includes tests, a changelog, a clear README, an MIT license, Composer tooling, and security scanning. Its small release history and inactive recent commit record leave less evidence of sustained maintenance, while all 17 workflow action references are unpinned.
60%
Total Score
75
100
94
50
The package runs a post-autoload-dump install-time script. This adds execution during installation, but the signal provides no evidence that the script is unsafe.
The package is about six months old and has only two releases, both published within roughly two hours, so there is limited evidence of an established release cadence.
There were no commits and no active maintainers in the last three months, leaving limited evidence of ongoing maintenance after the initial release burst.
The repository has no SECURITY.md policy, which reduces transparency for reporting vulnerabilities, though this is not evidence of a vulnerability itself.
All five workflows were analyzed successfully with no reported audit findings or untrusted checkouts. However, all 17 action references are unpinned and one workflow grants top-level write permissions, creating avoidable maintenance and workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
illuminate/notifications Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.