Documentation, tests, release notes, and security files provide a solid consumer and maintenance foundation. The project is still young, and ongoing work depends heavily on one contributor despite organization ownership.
70%
Total Score
70
100
89
70
One of three workflows uses pull_request_target. No untrusted checkout or script injection was detected, so the workflow profile is a limited caution rather than a severe risk.
A post-autoload-dump install script is present. This is a point to review because it runs during installation, but the signal provides no evidence that it is unsafe or unusually broad.
Only one registry account has publish access. That is a concern for release continuity, but it is partly offset by the repository being owned by an organization.
The package is only 44 days old with two releases, though the releases arrived about 3 days apart and show active early development. Its short history leaves long-term maintenance unproven.
One contributor made all 21 commits in the last 3 months, creating a low bus factor. Organization ownership provides some handoff capacity but does not show that another contributor is active.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.2 || ^8.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/database Version ^12.0 || ^13.0 | — | — |
illuminate/filesystem Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.