Clear licensing, usage documentation, repository tests, and a security policy support dependable adoption. Workflow references are unpinned and no security scanning is reported, so maintenance hygiene is not flawless.
84%
Total Score
100
100
89
100
Composer build tooling is used, but no security scanning tool is reported. The missing scanner is a modest process gap, not evidence of unsafe code by itself.
Version 0.10.0 is not a prerelease, and recent releases contain no prerelease versions. The pre-1.0 major version signals some API evolution risk, but not instability in this release.
Both workflows were analyzed successfully, with no untrusted checkouts, script injection, or audit findings, and no workflows use top-level write permissions. All seven action references are unpinned, which leaves a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3 | — | — |
psr/simple-cache Version ^2.0|^3.0 | — | — |
illuminate/config Version ^12.30|^13.0 | — | — |
illuminate/console Version ^12.30|^13.0 | — | — |
illuminate/routing Version ^12.30|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.