Tests, release notes, a matching source repository, and a recent release provide useful transparency. The tiny public footprint, absent security scanning, and unpinned workflow actions add uncertainty; pin this version while watching subsequent releases.
68%
Total Score
50
100
89
75
The registry namespace and repository owner match a single individual account. This is coherent ownership, but it does not provide organizational backing to offset the narrow maintainer base.
There were no commits from any active maintainer during the last three months. The release and repository push on the collection date partly compensate, but the short-term maintenance record remains thin.
The repository has zero stars, one fork, and one watcher. This does not establish abandonment, but it provides little external adoption evidence for a package intended for application integration.
Composer build tooling is present, but no security scanning tools are configured. That is a modest transparency and maintenance gap, not evidence of a security defect by itself.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or describing security handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
kreait/laravel-firebase Version ^7.0 | — | — |
illuminate/notifications Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.