The package is clearly documented and tested, with a permissive license and no install-time scripts. Its small repository has two active contributors and recent releases, while workflow references are unpinned and no security policy is provided.
82%
Total Score
100
93
67
Composer build tooling is present, but no security scanning tool was detected. The missing scanning is a modest transparency and maintenance gap, not evidence of unsafe code by itself.
The repository has no security policy. This weakens the project's documented vulnerability-reporting process, although recent commits, tests, and release notes provide compensating maintenance evidence.
The single workflow was fully analyzed with no detected injection or high-confidence audit findings, but all 3 action references are unpinned. That leaves avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
bounceshift/bounceshift-php Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.